PT-2021-17140 · Centreon · Centreon Web

Published

2021-05-04

·

Updated

2021-05-12

·

CVE-2021-26804

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Centreon Web versions 19.10.18, 20.04.8, and 20.10.2
Description The issue allows remote attackers to bypass validation by changing any file extension to ".gif" and then uploading it in the "Administration/ Parameters/ Images" section of the application. This is due to insecure permissions.
Recommendations For Centreon Web version 19.10.18, update to a version that fixes the insecure permissions issue. For Centreon Web version 20.04.8, update to a version that fixes the insecure permissions issue. For Centreon Web version 20.10.2, update to a version that fixes the insecure permissions issue. As a temporary workaround, consider restricting access to the "Administration/ Parameters/ Images" section to minimize the risk of exploitation.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26804

Affected Products

Centreon Web