vendor:
NagVis
by:
David RodrÃguez a.k.a. xerosec
6.1
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: NagVis
Affected Version From: 1.9.33
Affected Version To: 1.9.33
Patch Exists: YES
Related CWE: CVE-2022-46945
CPE: a:nagvis_project:nagvis:1.9.33
Platforms Tested: Linux
2024
NagVis 1.9.33 – Arbitrary File Read
NagVis version 1.9.33 is vulnerable to an arbitrary file read exploit. An attacker can read arbitrary files on the system by sending a crafted request to the '/nagvis/server/core/ajax_handler.php' endpoint with a file path parameter. This vulnerability has been assigned CVE-2022-46945.
Mitigation:
To mitigate this vulnerability, it is recommended to update NagVis to a patched version or apply the vendor-supplied fix. Additionally, restrict access to the affected endpoint and sanitize user inputs to prevent such attacks.