Nagios XI versions prior to 5.11.3 are affected by a SQL injection vulnerability in the bulk modification tool. The vulnerability allows an attacker to inject arbitrary SQL commands via crafted input to the tool, due to insufficient sanitization of user-supplied data before it is used in SQL queries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused Python proof-of-concept exploit for CVE-2023-48084 affecting Nagios XI before 5.11.3. The repo contains 4 files: a main Python exploit script (CVE-2023-48084.py), a README with usage and vulnerability context, a requirements.txt dependency file, and a .gitignore. The exploit is not part of a major exploitation framework. The main capability is authenticated time-based blind SQL injection against the Nagios XI endpoint /admin/banner_message-ajaxhelper.php?action=acknowledge_banner_message&id=. The script supports authentication using either a valid non-admin nagiosxi session cookie or an API token. It first tests whether the target appears vulnerable by measuring response delays, then uses CASE WHEN ... SLEEP(...) SQL payloads to infer true/false conditions from timing. Operationally, the script improves on an earlier PoC by adding binary-search extraction for both string length and character values, multithreaded extraction with ThreadPoolExecutor, configurable delay/threshold/max-length settings, and CLI options to skip discovery when the operator already knows the database, table, or columns. Based on the README and visible code, it can enumerate schemas, tables, and columns, then dump selected column data from a chosen table. The extracted result is database disclosure only; there is no reverse shell, file write, privilege escalation, or code execution payload. The exploit structure appears to include helper routines for per-thread HTTP sessions, timing-based GET requests, URL construction, vulnerability testing, length inference, character extraction, interactive selection of schemas/tables/columns, and final data dumping/display. It disables TLS verification warnings and uses requests for HTTP traffic, with optional pwntools progress output. Overall, this is a real, functional, operational blind-SQLi data-extraction PoC rather than a detector-only script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.