CVE-2019-16194: SQL Injection
Published Sep 25, 2019
·Updated
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svcid parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.
Affected Software
1 affected component
Centreon Centreon<=19.04.0
Remediation
Patch Available
Event History
Sep 25, 2019
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16194?
CVE-2019-16194 is a SQL injection vulnerability in Centreon through version 19.04.
2
How severe is CVE-2019-16194?
CVE-2019-16194 is classified as critical and has a severity rating of 9.8 out of 10.
3
What is the affected software?
The affected software is Centreon version 19.04.
4
How can an attacker exploit CVE-2019-16194?
An attacker can exploit CVE-2019-16194 by using the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php to perform SQL injection attacks.
5
Are there any available fixes for CVE-2019-16194?
Yes, fixes for CVE-2019-16194 are available in the Centreon GitHub repository.