cvedb.io
CVE-2021-3277
HIGH · CVSS 7.2
EPSS exploitation probability: 0%
Published 2021-06-07T22:15:07.827 · Last modified 2026-06-17T04:04:52.737

Summary

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

Affected products

nagios — nagios_xi

Does this affect you?

Add your gear to cvedb and we'll alert you only when nagios ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.