CVE-2018-19311: XSS
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
Other sources
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19311?
CVE-2018-19311 is a vulnerability in Centreon 3.4.x that allows XSS (Cross-Site Scripting) attacks.
How does CVE-2018-19311 work?
CVE-2018-19311 can be exploited by injecting malicious code via the Service field in the main.php?p=20201 URI.
What is the severity of CVE-2018-19311?
CVE-2018-19311 has a severity of 5.4 (medium).
How can the CVE-2018-19311 vulnerability be fixed?
To fix CVE-2018-19311, upgrade to Centreon 18.10.0 or later.
Where can I find more information about CVE-2018-19311?
You can find more information about CVE-2018-19311 at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-19311), [Centreon Documentation](https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html), [RootHC](http://www.roothc.com.br/1349-2/)