ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36867”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36867
Published
2025-10-30
CVSS:
8.7
ShadowTrackr CVSS:
6.3
Summary:
Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.