getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the nsid parameter.
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the commandhostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.