CVE-2018-21023: Code Injection
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the nsid parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-21023?
CVE-2018-21023 is a vulnerability in Centreon Web before 2.8.28 that allows authenticated attackers to execute arbitrary code.
How severe is CVE-2018-21023?
CVE-2018-21023 has a severity rating of 8.8 (high).
How does CVE-2018-21023 work?
CVE-2018-21023 allows authenticated attackers to execute arbitrary code by exploiting the ns_id parameter in getStats.php.
Which software versions are affected by CVE-2018-21023?
Centreon Web versions between 2.8 and 2.8.28, as well as versions between 18.10.0 and 18.10.5, are affected by CVE-2018-21023.
Are there any references for CVE-2018-21023?
Yes, you can find more information about CVE-2018-21023 at the following references: [1] http://www.openwall.com/lists/oss-security/2019/10/09/2 [2] https://github.com/centreon/centreon/pull/7083 [3] https://github.com/centreon/centreon/pull/7271