CVE-2024-23115: Centreon updateGroups SQL Injection Remote Code Execution Vulnerability
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.
The specific flaw exists within the updateGroups function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22295.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23115?
CVE-2024-23115 is considered a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-23115?
To fix CVE-2024-23115, upgrade to Centreon version 22.10.15 or later, as earlier versions are vulnerable.
What software is affected by CVE-2024-23115?
CVE-2024-23115 affects Centreon versions prior to 22.10.15.
Can CVE-2024-23115 be exploited remotely?
Yes, CVE-2024-23115 can be exploited remotely but requires authentication.
What type of vulnerability is CVE-2024-23115?
CVE-2024-23115 is an SQL Injection vulnerability that allows for remote code execution.