CVE-2018-11589

CRITICAL

Centreon 3.4.6 and Centreon Web 2.8.23 - SQL Injection via searchU, id, chartId, searchCurve, or host_id Parameters

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.

References (7)

Core 7
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6250
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6257
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6251
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6256
Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/releases
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6255

Scores

CVSS v3 9.8
EPSS 0.0215
EPSS Percentile 80.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
centreon/centreon 3.4.6
centreon/centreon_web 2.8.23
Published Jun 25, 2018
Tracked Since Feb 18, 2026