CVE-2021-37223Medium· 6.5▾ SunlitNagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI applicatio…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.5%
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.
nagios_xi <= 5.8.4Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-37345High· 7.8Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
CVE-2021-25298High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25297High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25296High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25299Medium· 6.1Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents