PT-2024-6880 · Centreon · Centreon

Published

2024-06-21

·

Updated

2024-11-06

·

CVE-2024-39842

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Centreon version 24.04.2
Description A SQL injection vulnerability in Centreon allows a remote high-privileged attacker to execute arbitrary SQL commands via user massive changes inputs. This vulnerability is related to the lack of protection of the SQL query structure, allowing an attacker to elevate their privileges and execute arbitrary code using a specially crafted SQL query.
Recommendations For Centreon version 24.04.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the updateContactServiceCommands MC, updateAccessGroupLinks, and updateContactHostCommands MC functions until a patch is available. Avoid using user massive changes inputs in the affected API endpoints until the issue is resolved.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-08103
CVE-2024-39842
ZDI-24-1322
ZDI-24-1458
ZDI-24-1460

Affected Products

Centreon