First published: Thu Jan 23 2025(Updated: )
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon | <24.10.3<24.04.9<23.10.19<23.04.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55573 is classified as a critical severity vulnerability.
To fix CVE-2024-55573, upgrade Centreon centreon-web to version 24.10.3 or later, 24.04.9 or later, 23.10.19 or later, or 23.04.24 or later.
CVE-2024-55573 is a SQL injection vulnerability affecting Centreon centreon-web.
Users with high privileges on Centreon centreon-web versions prior to the specified fixed versions are affected by CVE-2024-55573.
CVE-2024-55573 allows an attacker to inject SQL queries through forms used to create virtual metrics.