CVE-2018-11587: Code Injection
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11587?
CVE-2018-11587 is a vulnerability that allows remote code execution in Centreon 3.4.6 and Centreon Web 2.8.23.
How severe is CVE-2018-11587?
CVE-2018-11587 has a severity rating of 9.8, which is considered critical.
Which software versions are affected by CVE-2018-11587?
Centreon 3.4.6 and Centreon Web 2.8.23 are affected by CVE-2018-11587.
How can I fix CVE-2018-11587?
To fix CVE-2018-11587, update to Centreon Web 2.8.24 or Centreon 3.4.6.
Where can I find more information about CVE-2018-11587?
You can find more information about CVE-2018-11587 at the following references: - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-11587) - [Centreon Release Notes](https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html) - [GitHub Pull Request](https://github.com/centreon/centreon-archived/pull/6263)