ZDI-24-597: Centreon initCurveList SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-5725.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-597?
The severity of ZDI-24-597 is critical due to its potential to allow remote code execution.
How do I fix ZDI-24-597?
To fix ZDI-24-597, update Centreon to the latest patched version provided by the vendor.
Are there any specific conditions required to exploit ZDI-24-597?
Yes, authentication is required to exploit the ZDI-24-597 vulnerability.
What software is affected by ZDI-24-597?
ZDI-24-597 affects installations of Centreon Web.
What type of attack does ZDI-24-597 enable?
ZDI-24-597 enables remote attackers to execute arbitrary code on vulnerable systems.