First published: Fri Nov 16 2018(Updated: )
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the `main.php?p=20201` URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon | >=3.4.0<=3.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19311 is a vulnerability in Centreon 3.4.x that allows XSS (Cross-Site Scripting) attacks.
CVE-2018-19311 can be exploited by injecting malicious code via the Service field in the main.php?p=20201 URI.
CVE-2018-19311 has a severity of 5.4 (medium).
To fix CVE-2018-19311, upgrade to Centreon 18.10.0 or later.
You can find more information about CVE-2018-19311 at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-19311), [Centreon Documentation](https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html), [RootHC](http://www.roothc.com.br/1349-2/)