HIGH
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI
Published Nov 16, 2018
8.8
HIGHCVSS 3.0
EPSS 1.93%
Description
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://www.roothc.com.br/1349-2/ x_refsource_MISCExploitThird Party Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html x_refsource_CONFIRM
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2614 Advisory
- https://github.com/advisories/GHSA-5jxp-4x68-mhqc Advisory
- https://github.com/centreon/centreon-archived/pull/6257
- https://github.com/centreon/centreon-archived/pull/6628
- https://github.com/centreon/centreon/pull/6257 x_refsource_CONFIRM
- https://github.com/centreon/centreon/pull/6628 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2018-19312
| Link | Providers | Tags |
|---|---|---|
| http://www.roothc.com.br/1349-2/ | x_refsource_MISCExploitThird Party Advisory | |
| https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html | x_refsource_CONFIRM | |
| https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2614 | Advisory | |
| https://github.com/advisories/GHSA-5jxp-4x68-mhqc | Advisory | |
| https://github.com/centreon/centreon-archived/pull/6257 | ||
| https://github.com/centreon/centreon-archived/pull/6628 | ||
| https://github.com/centreon/centreon/pull/6257 | x_refsource_CONFIRM | |
| https://github.com/centreon/centreon/pull/6628 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-19312 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 16, 2018
Updated Aug 5, 2024
Reserved Nov 16, 2018
Link CVE-2018-19312
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-2614 GHSA-5JXP-4X68-MHQC Assigner mitre
Published Nov 16, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2022-2614