SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.Referenceshttps://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0fhttps://www.exploit-db.com/exploits/44560/https://www.nagios.com/downloads/nagios-xi/change-log/https://blog.redactedsec.net/exploits/2018/04/26/nagios.htmlhttps://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXThttps://www.exploit-db.com/exploits/44969/