Nagios Core 4.5.13 之前版本以及 Nagios XI 2026R1.5 之前版本在 中存在 CSRF(跨站请求伪造)漏洞。当请求中未包含 Cookie 头时,攻击者可以通过在 POST 请求体中提供相匹配的 和 值来绕过“双重提交 Cookie”防护机制,从而允许跨站请求以当前已认证用户的身份执行 Nagios 命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nagios Enterprises, LLC. | Nagios Core | < 4.5.13 |
affected |
| Nagios Enterprises, LLC. | Nagios XI | < 2026R1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nagios Enterprises, LLC. | Nagios Core | 0 ~ 4.5.13 | - |
|
| Nagios Enterprises, LLC. | Nagios XI | 0 ~ 2026R1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet