CRITICAL

CVE-2019-12279

CVSS v3

9.8

CRITICAL

EPSS Score

16.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luck

Technical details

Published
5/22/2019

Frequently asked questions

What is CVE-2019-12279?

Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luck

Is CVE-2019-12279 actively exploited?

Active exploitation of CVE-2019-12279 has not been confirmed. The EPSS score is 16.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-12279?

CVE-2019-12279 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-12279 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.