PT-2018-14912 · Centreon · Centreon
Published
2018-11-16
·
Updated
2022-05-14
·
CVE-2018-19311
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Centreon versions 3.4.x through 18.09.x
Description
The issue allows for XSS via the Service field to the "main.php?p=20201" URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
Recommendations
For Centreon versions 3.4.x through 18.09.x, update to Centreon 18.10.0 to resolve the issue.
As a temporary workaround, consider restricting access to the
main.php?p=20201 URI until a patch is available.
Avoid using the Service field in the affected URI until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centreon