CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-40931

Medium · CVSS 6.5

Nagios XI — SQL Injection (CWE-89)

CVSS
6.5
nvd
EPSS
KEV
No
Class
other
CWE-89

Description

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

Search profile — drives PoC discovery

Symbols banner_message-ajaxhelper.phpID/nagiosxi/admin/banner_message-ajaxhelper.php
Keywords CVE-2023-40931Nagios XISQL injectionbanner_message-ajaxhelpernagiosxi adminauthenticated SQLi5.11.05.11.1
Versions: 5.11.0 to 5.11.1

Ranked PoCs (5) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z