关键漏洞信息 标题: Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis 严重性: HIGH 日期: October 30, 2025 影响版本: XI < 2024R1.1.4 CVE编号: CVE-2024-14002 CWE编号: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') CVSS评分: 7.1 CVSS V4向量: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VL:N/VA:N/SC:N/SE:N/SA:N 参考链接: - Nagios XI Security Disclosures - Nagios XI Changelog 发现者: Mark Rakoczi 描述: Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host.