CVE-2019-15298

HIGH

Centreon Web 2.8.1-2.8.29 - Authenticated OS Command Injection via MIB Upload mnftr Parameter

Title source: llm
STIX 2.1

Description

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.2662
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
centreon/centreon_web 2.8.1 - 2.8.30
Published Nov 27, 2019
Tracked Since Feb 18, 2026