#VU53531 Improper access control in Nagios Fusion - CVE-2020-28911
Published: May 25, 2021
Nagios Fusion
nagios.org
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "test_server" command in ajaxhelper.php. A remote authenticated attacker can bypass implemented security restrictions and gain unauthorized access to sensitive information on the system.