First published: Wed Nov 27 2019(Updated: )
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon Web | >=2.8.1<2.8.30 | |
Centreon Centreon Web | >=19.04.0<19.04.5 | |
Centreon Centreon Web | >=19.10.0<19.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15300 is a vulnerability found in Centreon Web through version 19.04.3 that allows for an authenticated SQL injection attack.
The severity of CVE-2019-15300 is high, with a CVSS score of 8.8.
Centreon Web versions 2.8.1 to 2.8.30, 19.04.0 to 19.04.5, and 19.10.0 to 19.10.2 are affected by CVE-2019-15300.
To fix CVE-2019-15300, it is recommended to update Centreon Web to a version that is not affected by the vulnerability.
More information about CVE-2019-15300 can be found in the Centreon documentation and release notes.