CVE-2019-17642

HIGH

Centreon 18.0.0-18.10.8 - Unauthenticated Remote Code Execution via Autodiscovery Plugin CSRF

Title source: llm
STIX 2.1

Description

An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.

Scores

CVSS v3 8.8
EPSS 0.0164
EPSS Percentile 73.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352 CWE-78
Status published
Products (1)
centreon/centreon 18.0.0 - 18.10.8
Published Mar 05, 2020
Tracked Since Feb 18, 2026