Centreon SQL Injection
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Sep 15, 2023
Package
Affected versions
>= 18.0.0, < 18.10.0
>= 2.8.0, < 2.8.24
Patched versions
18.10.0
2.8.24
Description
Published by the National Vulnerability Database
Nov 16, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 21, 2023
Last updated
Sep 15, 2023
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
References