CVE-2018-19271

HIGH

Centreon <18.10.0-2.8.28 - SQL Injection

Title source: llm
STIX 2.1

Description

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.

Scores

CVSS v3 8.8
EPSS 0.0212
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (3)
centreon/centreon 3.4.1
centreon/centreon 3.4.6
centreon/centreon 18.0.0 - 18.10.0Packagist
Published Nov 14, 2018
Tracked Since Feb 18, 2026