CVE-2018-19280: XSS
Published Nov 14, 2018
·Updated
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
Affected Software
2 affected componentsFixes available
composer/centreon/centreon>=3.4.0<18.10.0
18.10.0
Centreon Centreon>=3.4.0<=3.4.9
Remediation
Patch Available
Event History
Nov 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 14, 2022
Advisory Published
12:55 AM
Frequently Asked Questions
1
What is CVE-2018-19280?
CVE-2018-19280 is a vulnerability found in Centreon 3.4.x, which allows for XSS attacks through the resource name or macro expression of a poller macro.
2
What is the severity of CVE-2018-19280?
The severity of CVE-2018-19280 is medium, with a severity value of 6.1.
3
How can I fix CVE-2018-19280?
To fix CVE-2018-19280, you need to update Centreon to version 18.10.0 or higher.
4
Where can I find more information about CVE-2018-19280?
You can find more information about CVE-2018-19280 on the NVD website and the Centreon documentation.
5
What is CWE-79?
CWE-79 is a common weakness enumeration category that refers to cross-site scripting (XSS) vulnerabilities.