CVE-2024-33852: SQL Injection
Published Aug 23, 2024
·Updated
A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
Affected Software
8 affected components
Centreon Centreon Web<24.04.3
Centreon Centreon Web<23.10.13
Centreon Centreon Web<23.04.19
Centreon Centreon Web<22.10.23
Centreon Centreon Web>=22.10.0<22.10.23
Centreon Centreon Web>=23.04.0<23.04.19
Centreon Centreon Web>=23.10.0<23.10.13
Centreon Centreon Web>=24.04.0<24.04.3
Event History
Aug 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33852?
CVE-2024-33852 is classified as a high-severity SQL Injection vulnerability.
2
How do I fix CVE-2024-33852?
To mitigate CVE-2024-33852, update Centreon Web to version 24.04.3 or later, or to 23.10.13 or later, 23.04.19 or later, or 22.10.23 or later.
3
What components are affected by CVE-2024-33852?
CVE-2024-33852 affects the Downtime component in various versions of Centreon Web.
4
What versions of Centreon Web are vulnerable to CVE-2024-33852?
Centreon Web versions before 24.04.3, 23.10.13, 23.04.19, and 22.10.23 are vulnerable to CVE-2024-33852.
5
Can CVE-2024-33852 lead to data compromise?
Yes, CVE-2024-33852 can potentially allow attackers to execute unauthorized SQL queries, leading to data compromise.