CVE-2024-45754

HIGH

Centreon BI Server <24.04.3,23.10.8,23.04.11,22.10.11 - Authenticat...

Title source: llm
STIX 2.1

Description

An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access.

Scores

CVSS v3 7.2
EPSS 0.0048
EPSS Percentile 38.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Published Oct 11, 2024
Tracked Since Feb 18, 2026