CRITICAL🇵🇱 Wersja polska

CVE-2022-46945

CVSS 9.1v3.1pub. 2023-05-26upd. 2025-11-03

Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Nagvis

    APP
    Nagvis
    < 1.9.34
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2024-47093HIGH8.8same product

Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS

CVE-2025-39665MEDIUM6.9same product

User enumeration w module Checkmk MultisiteAuth pakietu Nagvis w wersjach przed 1.9.48 pozwala niezauwierzytel...

CVE-2024-38866MEDIUM5.3same product

Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection

CVE-2024-47090MEDIUM5.1same product

Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS

CVE-2023-46287MEDIUM6.1same product

XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.