First published: Mon Sep 26 2022(Updated: )
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon | =20.10.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Centreon v20.10.18 is CVE-2022-40044.
The severity of CVE-2022-40044 is medium with a CVSS score of 5.4.
The affected software version of CVE-2022-40044 is Centreon v20.10.18.
The CWE category of CVE-2022-40044 is CWE-79 (Cross-Site Scripting).
Attackers can exploit CVE-2022-40044 by injecting a crafted payload via the esc_name parameter in Centreon's Configuration/Notifications/Escalations, allowing them to execute arbitrary web scripts or HTML.