CVE-2018-19271: SQL Injection
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19271?
CVE-2018-19271 is a vulnerability in Centreon 3.4.x that allows SQL Injection via the main.php searchH parameter.
What is the severity of CVE-2018-19271?
CVE-2018-19271 has a severity score of 8.8 (high).
Which versions of Centreon are affected by CVE-2018-19271?
Centreon versions 3.4.1 and 3.4.6 are affected by CVE-2018-19271.
How can I fix CVE-2018-19271?
To fix CVE-2018-19271, update to Centreon 18.10.0 or Centreon web 2.8.28.
Where can I find more information about CVE-2018-19271?
You can find more information about CVE-2018-19271 at the following references: [Reference 1](https://nvd.nist.gov/vuln/detail/CVE-2018-19271), [Reference 2](https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html), [Reference 3](https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.28.html).