An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15903
Reference (s):
- https://www.nagios.com/downloads/nagios-xi/change-log/

