CVE-2023-40931
Medium · CVSS 6.5Nagios XI — SQL Injection (CWE-89)
- CVSS
- 6.5
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-89
Description
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Search profile — drives PoC discovery
Symbols banner_message-ajaxhelper.phpID/nagiosxi/admin/banner_message-ajaxhelper.php
Keywords CVE-2023-40931Nagios XISQL injectionbanner_message-ajaxhelpernagiosxi adminauthenticated SQLi5.11.05.11.1
Versions: 5.11.0 to 5.11.1
Ranked PoCs (5) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 1sealldeveloper/CVE-2023-40931-PoC needs reviewgh_search
- ★ 0
- ★ 0YuchaoZheng88/HTB-prepare needs reviewtrickest
- ★ 0cyb3r-w0lf/nuclei-template-collection needs reviewtrickest
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z