CVE-2018-21024: Malicious File Upload
Published Oct 8, 2019
·Updated
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
Affected Software
1 affected component
Centreon Centreon<2.8.27
Remediation
Patch Available
Patch Available
Event History
Oct 8, 2019
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
Description
Frequently Asked Questions
1
What is CVE-2018-21024?
CVE-2018-21024 is a vulnerability in Centreon Web before version 2.8.27 that allows attackers to upload arbitrary files.
2
How severe is CVE-2018-21024?
CVE-2018-21024 has a severity of 9.8 (Critical).
3
What software versions are affected by CVE-2018-21024?
CVE-2018-21024 affects Centreon Web versions up to and excluding 2.8.27.
4
How can I fix CVE-2018-21024?
To fix CVE-2018-21024, you should upgrade Centreon Web to version 2.8.27 or above.
5
Where can I find more information about CVE-2018-21024?
You can find more information about CVE-2018-21024 at the following references: [1](http://www.openwall.com/lists/oss-security/2019/10/09/2), [2](https://github.com/centreon/centreon/pull/7085), [3](https://www.openwall.com/lists/oss-security/2019/10/08/1).