First published: Mon Jun 25 2018(Updated: )
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon | =3.4.6 | |
Centreon Centreon Web | =2.8.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11589 is a vulnerability in Centreon 3.4.6 including Centreon Web 2.8.23 that allows SQL injection attacks.
CVE-2018-11589 is classified as critical with a severity score of 9.8.
Centreon 3.4.6 and Centreon Web 2.8.23 are affected by CVE-2018-11589.
Attacks can exploit CVE-2018-11589 through the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_ parameter in various components.
Yes, fixes for CVE-2018-11589 can be found in the official Centreon release notes and GitHub pull requests.