PT-2024-5920 · Centreon · Centreon Web

Published

2024-08-23

·

Updated

2024-08-28

·

CVE-2024-33853

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Centreon Web versions 22.10.0 through 22.10.22 Centreon Web versions 23.04.0 through 23.04.18 Centreon Web versions 23.10.0 through 23.10.12 Centreon Web versions 24.04.0 through 24.04.2
Description A SQL Injection vulnerability exists in the Timeperiod component. This issue is related to the lack of protection of the SQL query structure, which may allow a remote attacker to execute arbitrary SQL commands.
Recommendations Update to version 22.10.23 to resolve the issue. Update to version 23.04.19 to resolve the issue. Update to version 23.10.13 to resolve the issue. Update to version 24.04.3 to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-06726
CVE-2024-33853

Affected Products

Centreon Web