CVE-2024-53923: SQL Injection
Published Jan 23, 2025
·Updated
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.
Affected Software
8 affected components
Centreon Web<24.10.3
Centreon Web<24.04.9
Centreon Web<23.10.19
Centreon Web<23.04.24
Centreon Centreon Web>=23.04.0<23.04.24
Centreon Centreon Web>=23.10.0<23.10.19
Centreon Centreon Web>=24.04.0<24.04.9
Centreon Centreon Web>=24.10.0<24.10.3
Event History
Jan 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53923?
CVE-2024-53923 has a critical severity rating due to the potential for SQL injection by privileged users.
2
How do I fix CVE-2024-53923?
To mitigate CVE-2024-53923, upgrade Centreon Web to versions 24.10.3, 24.04.9, 23.10.19, or 23.04.24 or later.
3
Which versions of Centreon Web are affected by CVE-2024-53923?
CVE-2024-53923 affects Centreon Web versions earlier than 24.10.3, 24.04.9, 23.10.19, and 23.04.24.
4
What type of vulnerability is CVE-2024-53923?
CVE-2024-53923 is an SQL injection vulnerability resulting from improper input validation.
5
Who is impacted by CVE-2024-53923?
Privileged users of affected versions of Centreon Web are at risk due to this SQL injection vulnerability.