CVE-2019-19487: OS Command Injection
Published Mar 20, 2020
·Updated
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
Affected Software
1 affected component
Centreon Centreon<=19.04.4
Remediation
Event History
Mar 20, 2020
CVE Published
via MITRE·02:36 AM
Data Sourced
via MITRE·02:36 AM
Description
Frequently Asked Questions
1
What is CVE-2019-19487?
CVE-2019-19487 is a command injection vulnerability in minPlayCommand.php in Centreon (19.04.4 and below), allowing an attacker to achieve command injection via a plugin test.
2
How severe is CVE-2019-19487?
CVE-2019-19487 has a severity score of 8.8 (high).
3
What software versions are affected by CVE-2019-19487?
Centreon versions up to and including 19.04.4 are affected by CVE-2019-19487.
4
How can an attacker exploit CVE-2019-19487?
An attacker can exploit CVE-2019-19487 by performing command injection through a plugin test in minPlayCommand.php.
5
Are there any references for CVE-2019-19487?
Yes, you can find more information about CVE-2019-19487 at the following link: https://medium.com/@mucomplex/undisclosed-cve-2019-19484-cve-2019-19486-cve-2019-19487-b46b97c930cd