CVE-2020-22425: SQL Injection
Published Feb 15, 2021
·Updated
Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.
Affected Software
1 affected component
Centreon Centreon=19.10
Event History
Feb 15, 2021
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22425?
CVE-2020-22425 is a SQL injection vulnerability in Centreon 19.10-3.el7.
2
What is the severity of CVE-2020-22425?
CVE-2020-22425 has a severity rating of 8.8 (high).
3
How does CVE-2020-22425 affect Centreon?
CVE-2020-22425 allows an authorized user to inject additional SQL queries in Centreon, which can lead to remote command execution.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-22425?
The CWE for CVE-2020-22425 is CWE-89 (SQL Injection).
5
How can I fix CVE-2020-22425?
To fix CVE-2020-22425, users should update to a patched version of Centreon and apply recommended security practices.