CVE-2018-19312: SQL Injection
Published Nov 16, 2018
·Updated
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
Affected Software
3 affected componentsFixes available
composer/centreon/centreon>=2.8.0<2.8.24
2.8.24
composer/centreon/centreon>=18.0.0<18.10.0
18.10.0
Centreon Centreon>=3.4.0<=3.4.9
Event History
Nov 16, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 14, 2022
Advisory Published
12:55 AM
Frequently Asked Questions
1
What is CVE-2018-19312?
CVE-2018-19312 is a SQL Injection vulnerability in Centreon 3.4.x that allows an attacker to inject malicious SQL code through the searchVM parameter.
2
How severe is CVE-2018-19312?
CVE-2018-19312 has a severity score of 8.8, which is considered high.
3
What software versions are affected by CVE-2018-19312?
Centreon 3.4.0 to 3.4.9, Centreon web 2.8.0 to 2.8.24, and Centreon 18.0.0 to 18.10.0 are affected by CVE-2018-19312.
4
How can I fix CVE-2018-19312?
To fix CVE-2018-19312, update Centreon to version 18.10.0 or later, Centreon web to version 2.8.24 or later, or apply the necessary patches.
5
Where can I find more information about CVE-2018-19312?
You can find more information about CVE-2018-19312 on the NIST National Vulnerability Database and Centreon's documentation.