The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.nagios.com/products/security/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Information
                Published : 2021-02-03 14:15
Updated : 2021-02-05 11:33
NVD link : CVE-2021-26024
Mitre link : CVE-2021-26024
JSON object : View
CWE
                Products Affected
                nagios
- favorites
- nagios_xi


