First published: Tue May 04 2021(Updated: )
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon Web | =19.10.18 | |
Centreon Centreon Web | =20.04.8 | |
Centreon Centreon Web | =20.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26804 is a vulnerability in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 that allows remote attackers to bypass validation by changing a file extension to ".gif" and uploading it in the "Administration/ Parameters/ Images" section of the application.
The severity of CVE-2021-26804 is medium, with a CVSS score of 6.5.
Remote attackers can exploit CVE-2021-26804 by changing a file extension to ".gif" and uploading it in the "Administration/ Parameters/ Images" section of Centreon Web.
Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 are affected by CVE-2021-26804.
To fix CVE-2021-26804, update to a version of Centreon Web that is not affected by the vulnerability or apply the necessary patches provided by Centreon.