The Core Configuration Manager in Nagios XI allows an authenticated user with privilege to manage host escalations to perform arbitrary database queries through the `/nagiosxi/includes/components/ccm/index.php` endpoint. The parameters `tfFirstNotif`, `tfLastNotif`, and `tfNotifInterval` are assumed to be trusted despite coming directly from the client through a POST request.