RULE(RULE ID:337095)

Rule General Information
Release Date: 2022-10-18
Rule Name: NagiosXI menuaccess.php SQL Injection Vulnerability (CVE-2018-10738)
Severity:
CVE ID:
Rule Protection Details
Description: A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://www.seebug.org/vuldb/ssvid-97268
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.nagios.com/