CVE-2021-25296
Description
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Summary dbcve.org
Nagios XI xi-5.7.5 contains an OS command injection vulnerability in the Windows WMI configuration wizard (windowswmi.inc.php). Authenticated users can inject arbitrary OS commands through unsanitized user input in a single HTTP request, leading to complete compromise of the Nagios XI server.
Mitigation
Upgrade to Nagios XI version 5.8.0 or later which contains the patched version of windowswmi.inc.php with proper input sanitization. If immediate patching is not possible, restrict access to the Windows WMI configuration wizard to only trusted administrators.