In nagios xi 5.7, admin can edit/delete/add template in /nagiosxi/admin/graphtemplates.php the template will be store in /usr/local/nagios/share/pnp/templates . Which can be accessed and execute as a PHP file through /nagios/pnp/templates/?.php. and lead to PHP code execution and OS command execution as apache.

