PT-2021-4024 · Mediawiki+1 · Mediawiki+1
Published
2021-04-02
·
Updated
2021-08-10
·
CVE-2021-37558
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Centreon versions prior to 20.04.14
Centreon versions prior to 20.10.8
Centreon versions prior to 21.04.2
Description
The issue is related to a lack of protection against SQL query structure exploitation in the MediaWiki script used by Centreon. This allows a remote attacker to execute arbitrary SQL commands using the
host name and service description parameters. The vulnerability can only be exploited when a valid Knowledge Base URL is configured and points to a MediaWiki instance, relating to the proxy feature in specific Centreon classes and configuration files.Recommendations
For Centreon versions prior to 20.04.14, update to version 20.04.14 or later.
For Centreon versions prior to 20.10.8, update to version 20.10.8 or later.
For Centreon versions prior to 21.04.2, update to version 21.04.2 or later.
As a temporary workaround, consider restricting access to the
host name and service description parameters in the affected MediaWiki script until a patch is available.
Restrict access to the proxy feature in class/centreon-knowledge/ProceduresProxy.class.php and include/configuration/configKnowledge/proxy/proxy.php to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centreon
Mediawiki