First published: Wed Nov 27 2019(Updated: )
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon Web | >=2.8.1<2.8.30 | |
Centreon Centreon Web | >=18.10.0<18.10.8 | |
Centreon Centreon Web | >=19.04.0<19.04.5 | |
Centreon Centreon Web | >=19.10.0<19.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15298 is a vulnerability found in Centreon Web through 19.04.3 that allows authenticated command injection.
The severity of CVE-2019-15298 is high, with a CVSS score of 8.8.
CVE-2019-15298 affects Centreon Web versions 2.8.1 to 2.8.30, 18.10.0 to 18.10.8, 19.04.0 to 19.04.5, and 19.10.0 to 19.10.2.
CVE-2019-15298 has CWE (Common Weakness Enumeration) identifiers 77 and 78.
To fix CVE-2019-15298, it is recommended to apply the necessary patches provided by Centreon and upgrade to a secure version.