CVE-2024-14002 | Nagios XI up to 2024R1.1.3 NagVis filename control
A vulnerability was found in Nagios XI up to 2024R1.1.3. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component NagVis. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is documented as CVE-2024-14002. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is recommended.