CVE-2018-11589
CRITICALCentreon 3.4.6 and Centreon Web 2.8.23 - SQL Injection via searchU, id, chartId, searchCurve, or host_id Parameters
Title source: llmDescription
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.
References (7)
Core 7
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6250
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6257
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6251
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6256
Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/releases
Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/6255
Release Notes, Vendor Advisory x_refsource_confirm
https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html
Scores
CVSS v3
9.8
EPSS
0.0215
EPSS Percentile
80.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (2)
centreon/centreon
3.4.6
centreon/centreon_web
2.8.23
Published
Jun 25, 2018
Tracked Since
Feb 18, 2026