CVE-2018-11589: SQL Injection
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the hostid parameter in makeXMLListMetrics.php.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-11589?
CVE-2018-11589 is a vulnerability in Centreon 3.4.6 including Centreon Web 2.8.23 that allows SQL injection attacks.
How severe is CVE-2018-11589?
CVE-2018-11589 is classified as critical with a severity score of 9.8.
What software versions are affected by CVE-2018-11589?
Centreon 3.4.6 and Centreon Web 2.8.23 are affected by CVE-2018-11589.
How can attacks exploit CVE-2018-11589?
Attacks can exploit CVE-2018-11589 through the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_ parameter in various components.
Are there any fixes or patches available for CVE-2018-11589?
Yes, fixes for CVE-2018-11589 can be found in the official Centreon release notes and GitHub pull requests.