<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Centreon (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/centreon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/centreon-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Centreon (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-2750 – Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Cen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2750</guid>
    <pubDate>Fri, 27 Feb 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2750</strong></p>
  <p>Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2749 – Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Cent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2749</guid>
    <pubDate>Fri, 27 Feb 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2749</strong></p>
  <p>Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2751 – Blind SQL Injection via unsanitized array keys in Service Dependencies deletion...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2751</guid>
    <pubDate>Fri, 27 Feb 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2751</strong></p>
  <p>Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15029 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15029</guid>
    <pubDate>Mon, 05 Jan 2026 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15029</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15026 – Missing Authentication for Critical Function vulnerability in Centreon Infra Mon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15026</guid>
    <pubDate>Mon, 05 Jan 2026 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15026</strong></p>
  <p>Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5965 – In the backup parameters, a user with high privilege is able to concatenate cust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5965</guid>
    <pubDate>Mon, 05 Jan 2026 10:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5965</strong></p>
  <p>In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setup modules) allows OS Command Injection.This issue affects Infra Monitoring: from 25.10.0 before 25.1…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12514 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12514</guid>
    <pubDate>Mon, 22 Dec 2025 11:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12514</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows   SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8432 – Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8432</guid>
    <pubDate>Mon, 27 Oct 2025 10:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8432</strong></p>
  <p>Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8459 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8459</guid>
    <pubDate>Tue, 14 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8459</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Monitoring recurrent downtime scheduler modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5946 – Improper Neutralization of Special Elements used in an OS Command ('OS Command I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5946</guid>
    <pubDate>Tue, 14 Oct 2025 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5946</strong></p>
  <p>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameters page, a user with high privilege is able to concatenate custom instructions into the poller reload command.  This issue affects Infra Monitoring: from 24.10.0 b…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6791 – In the monitoring event logs page, it is possible to alter the http request to i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6791</guid>
    <pubDate>Fri, 22 Aug 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6791</strong></p>
  <p>In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4648 – The content of a SVG file, received as input 

in Centreon web, was not properly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4648</guid>
    <pubDate>Tue, 13 May 2025 10:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4648</strong></p>
  <p>The content of a SVG file, received as input   in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.1…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4647 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4647</guid>
    <pubDate>Tue, 13 May 2025 10:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4647</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS.  A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG.  This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27,…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4646 – Incorrect Authorization vulnerability in Centreon web (API Token creation form m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4646</guid>
    <pubDate>Tue, 13 May 2025 10:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4646</strong></p>
  <p>Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3872 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3872</guid>
    <pubDate>Thu, 24 Apr 2025 10:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3872</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection.   A user with high privileges is able to become administrator by intercepting the contact form request and altering its payload.    This issue affects Centreon: from 22.10.0 before 22.10.28, from 23.04.0 before 23.04.25…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3767 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3767</guid>
    <pubDate>Tue, 22 Apr 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3767</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection.   This page is only accessible to authenticated users with high privileges.  This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55573 – An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55573</guid>
    <pubDate>Thu, 23 Jan 2025 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55573</strong></p>
  <p>An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-53923 – An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53923</guid>
    <pubDate>Thu, 23 Jan 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-53923</strong></p>
  <p>An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45757 – An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45757</guid>
    <pubDate>Tue, 03 Dec 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45757</strong></p>
  <p>An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45756 – An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45756</guid>
    <pubDate>Mon, 25 Nov 2024 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45756</strong></p>
  <p>An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45755 – An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45755</guid>
    <pubDate>Mon, 25 Nov 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45755</strong></p>
  <p>An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45754 – An issue was discovered in the centreon-bi-server component in Centreon BI Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45754</guid>
    <pubDate>Fri, 11 Oct 2024 22:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45754</strong></p>
  <p>An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39842 – A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39842</guid>
    <pubDate>Mon, 23 Sep 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39842</strong></p>
  <p>A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39841 – A SQL Injection vulnerability exists in the service configuration functionality ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39841</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39841</strong></p>
  <p>A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33854 – A SQL Injection vulnerability exists in the Graph Template component in Centreon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33854</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33854</strong></p>
  <p>A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33853 – A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33853</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33853</strong></p>
  <p>A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33852 – A SQL Injection vulnerability exists in the Downtime component in Centreon Web 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33852</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33852</strong></p>
  <p>A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-32501 – A SQL Injection vulnerability exists in the updateServiceHost functionality in C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32501</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-32501</strong></p>
  <p>A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5725 – Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5725</guid>
    <pubDate>Wed, 21 Aug 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5725</strong></p>
  <p>Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5723 – Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5723</guid>
    <pubDate>Wed, 21 Aug 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5723</strong></p>
  <p>Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateServiceHost function. The issue results from the lack of proper validation of a user-supplied string before usin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-51633 – Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51633</guid>
    <pubDate>Fri, 03 May 2024 03:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-51633</strong></p>
  <p>Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability.  The specific flaw exists within the processing of the sysName OID in SNMP. The issue results from the lack of proper validation of user-supplied data, whic…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23119 – Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23119</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23119</strong></p>
  <p>Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the insertGraphTemplate function. The issue results from the lack of proper validation of a user-supplied string before…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23118 – Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23118</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23118</strong></p>
  <p>Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateContactHostCommands function. The issue results from the lack of proper validation of a user-supplied st…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23117 – Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23117</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23117</strong></p>
  <p>Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateContactServiceCommands function. The issue results from the lack of proper validation of a user-suppl…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23116 – Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23116</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23116</strong></p>
  <p>Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateLCARelation function. The issue results from the lack of proper validation of a user-supplied string before usin…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23115 – Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23115</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23115</strong></p>
  <p>Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateGroups function. The issue results from the lack of proper validation of a user-supplied string before using it to co…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0637 – Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0637</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0637</strong></p>
  <p>Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateDirectory function. The issue results from the lack of proper validation of a user-supplied string before using it…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42429 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42429</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42429</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42428 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42428</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42428</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42427 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42427</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42427</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42426 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42426</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42426</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42425 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42425</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42425</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42424 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42424</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42424</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41142 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41142</guid>
    <pubDate>Thu, 26 Jan 2023 18:59:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41142</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage th…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-40043 – Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40043</guid>
    <pubDate>Mon, 26 Sep 2022 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-40043</strong></p>
  <p>Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34871 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34871</guid>
    <pubDate>Wed, 03 Aug 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34871</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22345 – /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22345</guid>
    <pubDate>Wed, 18 Aug 2021 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22345</strong></p>
  <p>/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37558 – A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37558</guid>
    <pubDate>Tue, 03 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37558</strong></p>
  <p>A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a valid Knowledge Base URL is configured on the Knowledge Base configuration page and points to a MediaWiki instance. This r…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37557 – A SQL injection vulnerability in image generation in Centreon before 20.04.14, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37557</guid>
    <pubDate>Tue, 03 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37557</strong></p>
  <p>A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37556 – A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37556</guid>
    <pubDate>Tue, 03 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37556</strong></p>
  <p>A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28053 – An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28053</guid>
    <pubDate>Fri, 16 Jul 2021 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28053</strong></p>
  <p>An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Contacts / Users" allows remote authenticated users to execute arbitrary SQL commands via the Additional Information parameters.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22425 – Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22425</guid>
    <pubDate>Mon, 15 Feb 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22425</strong></p>
  <p>Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13252 – Centreon before 19.04.15 allows remote attackers to execute arbitrary OS command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13252</guid>
    <pubDate>Thu, 21 May 2020 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13252</strong></p>
  <p>Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19699 – There is Authenticated remote code execution in Centreon Infrastructure Monitori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19699</guid>
    <pubDate>Mon, 06 Apr 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19699</strong></p>
  <p>There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19487 – Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19487</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19487</strong></p>
  <p>Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17647 – An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17647</guid>
    <pubDate>Thu, 05 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17647</strong></p>
  <p>An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17646 – An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17646</guid>
    <pubDate>Thu, 05 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17646</strong></p>
  <p>An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17645 – An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17645</guid>
    <pubDate>Thu, 05 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17645</strong></p>
  <p>An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17642 – An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17642</guid>
    <pubDate>Thu, 05 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17642</strong></p>
  <p>An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17644 – An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17644</guid>
    <pubDate>Wed, 04 Mar 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17644</strong></p>
  <p>An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17643 – An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17643</guid>
    <pubDate>Wed, 04 Mar 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17643</strong></p>
  <p>An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9463 – Centreon 19.10 allows remote authenticated users to execute arbitrary OS command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9463</guid>
    <pubDate>Fri, 28 Feb 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9463</strong></p>
  <p>Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15299 – An issue was discovered in Centreon Web through 19.04.3. When a user changes his...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15299</guid>
    <pubDate>Mon, 24 Feb 2020 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15299</strong></p>
  <p>An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20327 – Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Soft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20327</guid>
    <pubDate>Thu, 16 Jan 2020 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20327</strong></p>
  <p>Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15300 – A problem was found in Centreon Web through 19.04.3. An authenticated SQL inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15300</guid>
    <pubDate>Wed, 27 Nov 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15300</strong></p>
  <p>A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15298 – A problem was found in Centreon Web through 19.04.3. An authenticated command in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15298</guid>
    <pubDate>Wed, 27 Nov 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15298</strong></p>
  <p>A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filter…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16406 – Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16406</guid>
    <pubDate>Thu, 21 Nov 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16406</strong></p>
  <p>Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16405 – Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16405</guid>
    <pubDate>Thu, 21 Nov 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16405</strong></p>
  <p>Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17501 – Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17501</guid>
    <pubDate>Mon, 14 Oct 2019 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17501</strong></p>
  <p>Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-2019-16405 are similar to one another and may be the same.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-21024 – licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21024</guid>
    <pubDate>Tue, 08 Oct 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-21024</strong></p>
  <p>licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17107 – minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17107</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17107</strong></p>
  <p>minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17104 – In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17104</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17104</strong></p>
  <p>In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-565</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-21025 – In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become ro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21025</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-21025</strong></p>
  <p>In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21023 – getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21023</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21023</strong></p>
  <p>getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21022 – makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21022</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21022</strong></p>
  <p>makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21021 – img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21021</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21021</strong></p>
  <p>img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21020 – In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21020</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21020</strong></p>
  <p>In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16194 – SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the sv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16194</guid>
    <pubDate>Wed, 25 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16194</strong></p>
  <p>SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13024 – Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13024</guid>
    <pubDate>Mon, 01 Jul 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13024</strong></p>
  <p>Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19312 – Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19312</guid>
    <pubDate>Fri, 16 Nov 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19312</strong></p>
  <p>Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-19281 – Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19281</guid>
    <pubDate>Wed, 14 Nov 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-19281</strong></p>
  <p>Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19271 – Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19271</guid>
    <pubDate>Wed, 14 Nov 2018 11:29:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19271</strong></p>
  <p>Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11589 – Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11589</guid>
    <pubDate>Mon, 25 Jun 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11589</strong></p>
  <p>Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11587 – There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11587</guid>
    <pubDate>Mon, 25 Jun 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11587</strong></p>
  <p>There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1560 – SQL injection vulnerability in the isUserAdmin function in include/common/common...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1560</guid>
    <pubDate>Tue, 14 Jul 2015 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1560</strong></p>
  <p>SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-3829 – displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3829</guid>
    <pubDate>Thu, 23 Oct 2014 01:55:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-3829</strong></p>
  <p>displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-3828 – Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3828</guid>
    <pubDate>Thu, 23 Oct 2014 01:55:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-3828</strong></p>
  <p>Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the session_id parameter to views/graphs/graphStatus/displayServiceStatus.php, (4)…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1301 – SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1301</guid>
    <pubDate>Wed, 07 Apr 2010 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1301</strong></p>
  <p>SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-4368 – Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4368</guid>
    <pubDate>Mon, 21 Dec 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-4368</strong></p>
  <p>Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authentication.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-6485 – Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6485</guid>
    <pubDate>Thu, 20 Dec 2007 20:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-6485</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6485">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
