CVE-2019-15300: SQL Injection
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldaphost.php. The arId parameter is not properly filtered before being passed to the SQL query.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-15300?
CVE-2019-15300 is a vulnerability found in Centreon Web through version 19.04.3 that allows for an authenticated SQL injection attack.
What is the severity of CVE-2019-15300?
The severity of CVE-2019-15300 is high, with a CVSS score of 8.8.
What software is affected by CVE-2019-15300?
Centreon Web versions 2.8.1 to 2.8.30, 19.04.0 to 19.04.5, and 19.10.0 to 19.10.2 are affected by CVE-2019-15300.
How can I fix CVE-2019-15300?
To fix CVE-2019-15300, it is recommended to update Centreon Web to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-15300?
More information about CVE-2019-15300 can be found in the Centreon documentation and release notes.