PT-2018-10688 · Centreon · Centreon+1
Published
2018-06-25
·
Updated
2018-08-28
·
CVE-2018-11589
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Centreon version 3.4.6
Centreon Web version 2.8.23
Description
The issue allows for SQL injection attacks through various parameters in different PHP files. Specifically, attacks can be launched via the
searchU parameter in "viewLogs.php", the id parameter in "GetXmlHost.php", the chartId parameter in "ExportCSVServiceData.php", the searchCurve parameter in "listComponentTemplates.php", or the host id parameter in "makeXML ListMetrics.php".Recommendations
For Centreon version 3.4.6, avoid using the
searchU parameter in "viewLogs.php", the id parameter in "GetXmlHost.php", the chartId parameter in "ExportCSVServiceData.php", the searchCurve parameter in "listComponentTemplates.php", or the host id parameter in "makeXML ListMetrics.php" until a patch is available.
For Centreon Web version 2.8.23, consider restricting access to the aforementioned PHP files to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centreon
Centreon Web