HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon
Published Mar 29, 2023
8.8
HIGHCVSS 3.1
EPSS 2.87%
Description
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18410.
Affected products
-
- Version 22.04StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45502 Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-1399/ Third Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45502 | Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1399/ | Third Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner zdi
Published Mar 29, 2023
Updated Feb 14, 2025
Reserved Oct 3, 2022
Link CVE-2022-42428
CISA Vulnrichment
Updated Feb 14, 2025
ENISA EUVD
EUVD-2022-45502 Assigner zdi
Published Mar 29, 2023
Updated Feb 14, 2025
Exploited since n/a
Link EUVD-2022-45502