CVE-2022-40044: XSS
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the escname (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Centreonto a version that resolves this vulnerability.Fixed in 20.10.18
Event History
Frequently Asked Questions
What is the vulnerability ID for Centreon v20.10.18?
The vulnerability ID for Centreon v20.10.18 is CVE-2022-40044.
What is the severity of CVE-2022-40044?
The severity of CVE-2022-40044 is medium with a CVSS score of 5.4.
What is the affected software version of CVE-2022-40044?
The affected software version of CVE-2022-40044 is Centreon v20.10.18.
What is the CWE category of CVE-2022-40044?
The CWE category of CVE-2022-40044 is CWE-79 (Cross-Site Scripting).
How can attackers exploit CVE-2022-40044?
Attackers can exploit CVE-2022-40044 by injecting a crafted payload via the esc_name parameter in Centreon's Configuration/Notifications/Escalations, allowing them to execute arbitrary web scripts or HTML.