<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Centreon</title>
  <link>https://cvedaily.com/pages/tags/centreon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/centreon.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Centreon</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-2750 – Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Cen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2750</guid>
    <pubDate>Fri, 27 Feb 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2750</strong></p>
  <p>Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2749 – Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Cent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2749</guid>
    <pubDate>Fri, 27 Feb 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2749</strong></p>
  <p>Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2751 – Blind SQL Injection via unsanitized array keys in Service Dependencies deletion...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2751</guid>
    <pubDate>Fri, 27 Feb 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2751</strong></p>
  <p>Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15029 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15029</guid>
    <pubDate>Mon, 05 Jan 2026 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15029</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15026 – Missing Authentication for Critical Function vulnerability in Centreon Infra Mon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15026</guid>
    <pubDate>Mon, 05 Jan 2026 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15026</strong></p>
  <p>Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12513 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12513</guid>
    <pubDate>Mon, 05 Jan 2026 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12513</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts configuration form modules) allows Stored XSS to users with high privileges.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12511 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12511</guid>
    <pubDate>Mon, 05 Jan 2026 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12511</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configuration modules) allows Stored XSS   to user with elevated privileges.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.1, from 24.10.0 before 24.10.4, from 24.04.0 before 24.04.8.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13056 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13056</guid>
    <pubDate>Mon, 05 Jan 2026 11:17:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13056</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Administration ACL menu configuration modules)   allows Stored XSS to users with high privileges.  This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12519 – Missing Authorization vulnerability in Centreon Infra Monitoring (Administration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12519</guid>
    <pubDate>Mon, 05 Jan 2026 11:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12519</strong></p>
  <p>Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5965 – In the backup parameters, a user with high privilege is able to concatenate cust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5965</guid>
    <pubDate>Mon, 05 Jan 2026 10:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5965</strong></p>
  <p>In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setup modules) allows OS Command Injection.This issue affects Infra Monitoring: from 25.10.0 before 25.1…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8460 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8460</guid>
    <pubDate>Mon, 22 Dec 2025 11:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8460</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module)   allows Stored   XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54890 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54890</guid>
    <pubDate>Mon, 22 Dec 2025 11:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54890</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration page) allows Stored   XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19, from 23.10.0 before 23.10.29.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12514 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12514</guid>
    <pubDate>Mon, 22 Dec 2025 11:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12514</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows   SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10023 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10023</guid>
    <pubDate>Mon, 27 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10023</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules)   allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8432 – Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8432</guid>
    <pubDate>Mon, 27 Oct 2025 10:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8432</strong></p>
  <p>Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8459 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8459</guid>
    <pubDate>Tue, 14 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8459</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Monitoring recurrent downtime scheduler modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8430 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8430</guid>
    <pubDate>Tue, 14 Oct 2025 17:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8430</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Commands Connectors configuration modules) allows Stored   XSS by users with elevated privileges.  This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8429 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8429</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8429</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Action access configuration modules) allows Stored    XSS by users with elevated privileges.  This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54893 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54893</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54893</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts templates configuration modules) allows Stored    XSS by users with elevated privileges.  This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8428 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8428</guid>
    <pubDate>Tue, 14 Oct 2025 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8428</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (HTTP Loader widget modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5946 – Improper Neutralization of Special Elements used in an OS Command ('OS Command I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5946</guid>
    <pubDate>Tue, 14 Oct 2025 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5946</strong></p>
  <p>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameters page, a user with high privilege is able to concatenate custom instructions into the poller reload command.  This issue affects Infra Monitoring: from 24.10.0 b…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54892 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54892</guid>
    <pubDate>Tue, 14 Oct 2025 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54892</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules)   allows Stored XSS by users with elevated privileges.  This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54891 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54891</guid>
    <pubDate>Tue, 14 Oct 2025 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54891</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Resource access configuration modules) allows Stored   XSS by users with elevated privileges.  This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54889 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54889</guid>
    <pubDate>Tue, 14 Oct 2025 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54889</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps manufacturer configuration modules) allows Stored XSS by users with elevated privileges.  This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6791 – In the monitoring event logs page, it is possible to alter the http request to i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6791</guid>
    <pubDate>Fri, 22 Aug 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6791</strong></p>
  <p>In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4649 – Improper Handling of Exceptional Conditions vulnerability in Centreon web allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4649</guid>
    <pubDate>Tue, 13 May 2025 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4649</strong></p>
  <p>Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation.    ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.0…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4648 – The content of a SVG file, received as input 

in Centreon web, was not properly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4648</guid>
    <pubDate>Tue, 13 May 2025 10:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4648</strong></p>
  <p>The content of a SVG file, received as input   in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.1…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4647 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4647</guid>
    <pubDate>Tue, 13 May 2025 10:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4647</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS.  A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG.  This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27,…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4646 – Incorrect Authorization vulnerability in Centreon web (API Token creation form m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4646</guid>
    <pubDate>Tue, 13 May 2025 10:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4646</strong></p>
  <p>Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3872 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3872</guid>
    <pubDate>Thu, 24 Apr 2025 10:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3872</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection.   A user with high privileges is able to become administrator by intercepting the contact form request and altering its payload.    This issue affects Centreon: from 22.10.0 before 22.10.28, from 23.04.0 before 23.04.25…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3767 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3767</guid>
    <pubDate>Tue, 22 Apr 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3767</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection.   This page is only accessible to authenticated users with high privileges.  This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55573 – An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55573</guid>
    <pubDate>Thu, 23 Jan 2025 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55573</strong></p>
  <p>An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-53923 – An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53923</guid>
    <pubDate>Thu, 23 Jan 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-53923</strong></p>
  <p>An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45757 – An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45757</guid>
    <pubDate>Tue, 03 Dec 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45757</strong></p>
  <p>An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45756 – An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45756</guid>
    <pubDate>Mon, 25 Nov 2024 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45756</strong></p>
  <p>An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45755 – An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45755</guid>
    <pubDate>Mon, 25 Nov 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45755</strong></p>
  <p>An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47863 – An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47863</guid>
    <pubDate>Fri, 22 Nov 2024 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47863</strong></p>
  <p>An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 24.04.8, 23.10.x before 23.10.18, 23.04.x before 23.04.23, and 22.10.x before 22.10.26. A stored XSS was found in the user configuration contact name field. This form is only accessible to authenticated users with high-privilege access.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45754 – An issue was discovered in the centreon-bi-server component in Centreon BI Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45754</guid>
    <pubDate>Fri, 11 Oct 2024 22:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45754</strong></p>
  <p>An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39843 – A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39843</guid>
    <pubDate>Mon, 23 Sep 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39843</strong></p>
  <p>A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39842 – A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39842</guid>
    <pubDate>Mon, 23 Sep 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39842</strong></p>
  <p>A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39841 – A SQL Injection vulnerability exists in the service configuration functionality ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39841</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39841</strong></p>
  <p>A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33854 – A SQL Injection vulnerability exists in the Graph Template component in Centreon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33854</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33854</strong></p>
  <p>A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33853 – A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33853</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33853</strong></p>
  <p>A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33852 – A SQL Injection vulnerability exists in the Downtime component in Centreon Web 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33852</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33852</strong></p>
  <p>A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-32501 – A SQL Injection vulnerability exists in the updateServiceHost functionality in C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32501</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-32501</strong></p>
  <p>A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5725 – Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5725</guid>
    <pubDate>Wed, 21 Aug 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5725</strong></p>
  <p>Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5723 – Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5723</guid>
    <pubDate>Wed, 21 Aug 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5723</strong></p>
  <p>Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateServiceHost function. The issue results from the lack of proper validation of a user-supplied string before usin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-51633 – Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51633</guid>
    <pubDate>Fri, 03 May 2024 03:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-51633</strong></p>
  <p>Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability.  The specific flaw exists within the processing of the sysName OID in SNMP. The issue results from the lack of proper validation of user-supplied data, whic…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23119 – Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23119</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23119</strong></p>
  <p>Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the insertGraphTemplate function. The issue results from the lack of proper validation of a user-supplied string before…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23118 – Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23118</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23118</strong></p>
  <p>Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateContactHostCommands function. The issue results from the lack of proper validation of a user-supplied st…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23117 – Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23117</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23117</strong></p>
  <p>Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateContactServiceCommands function. The issue results from the lack of proper validation of a user-suppl…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23116 – Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23116</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23116</strong></p>
  <p>Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateLCARelation function. The issue results from the lack of proper validation of a user-supplied string before usin…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23115 – Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23115</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23115</strong></p>
  <p>Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateGroups function. The issue results from the lack of proper validation of a user-supplied string before using it to co…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0637 – Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0637</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0637</strong></p>
  <p>Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.  The specific flaw exists within the updateDirectory function. The issue results from the lack of proper validation of a user-supplied string before using it…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42429 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42429</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42429</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42428 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42428</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42428</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42427 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42427</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42427</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42426 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42426</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42426</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42425 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42425</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42425</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42424 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42424</guid>
    <pubDate>Wed, 29 Mar 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42424</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can lev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41142 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41142</guid>
    <pubDate>Thu, 26 Jan 2023 18:59:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41142</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage th…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3827 – A vulnerability was found in centreon. It has been declared as critical. This vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3827</guid>
    <pubDate>Wed, 02 Nov 2022 13:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3827</strong></p>
  <p>A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. The name of the patch is 293b10628f7d9f83c6c82c78cf637cbe9b907369. It is recommended to apply a patch to fix this…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-707</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39988 – A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39988</guid>
    <pubDate>Thu, 06 Oct 2022 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39988</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40044 – Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40044</guid>
    <pubDate>Mon, 26 Sep 2022 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40044</strong></p>
  <p>Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-40043 – Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40043</guid>
    <pubDate>Mon, 26 Sep 2022 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-40043</strong></p>
  <p>Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36194 – Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36194</guid>
    <pubDate>Mon, 29 Aug 2022 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36194</strong></p>
  <p>Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34872 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34872</guid>
    <pubDate>Wed, 03 Aug 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34872</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of Virtual Metrics. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnera…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34871 – This vulnerability allows remote attackers to escalate privileges on affected in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34871</guid>
    <pubDate>Wed, 03 Aug 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34871</strong></p>
  <p>This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22345 – /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22345</guid>
    <pubDate>Wed, 18 Aug 2021 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22345</strong></p>
  <p>/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37558 – A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37558</guid>
    <pubDate>Tue, 03 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37558</strong></p>
  <p>A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a valid Knowledge Base URL is configured on the Knowledge Base configuration page and points to a MediaWiki instance. This r…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37557 – A SQL injection vulnerability in image generation in Centreon before 20.04.14, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37557</guid>
    <pubDate>Tue, 03 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37557</strong></p>
  <p>A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37556 – A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37556</guid>
    <pubDate>Tue, 03 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37556</strong></p>
  <p>A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28053 – An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28053</guid>
    <pubDate>Fri, 16 Jul 2021 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28053</strong></p>
  <p>An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Contacts / Users" allows remote authenticated users to execute arbitrary SQL commands via the Additional Information parameters.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28054 – An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28054</guid>
    <pubDate>Fri, 16 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28054</strong></p>
  <p>An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27676 – Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27676</guid>
    <pubDate>Wed, 26 May 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27676</strong></p>
  <p>Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26804 – Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26804</guid>
    <pubDate>Tue, 04 May 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26804</strong></p>
  <p>Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28055 – An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28055</guid>
    <pubDate>Thu, 15 Apr 2021 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28055</strong></p>
  <p>An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22425 – Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22425</guid>
    <pubDate>Mon, 15 Feb 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22425</strong></p>
  <p>Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13628 – Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13628</guid>
    <pubDate>Wed, 27 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13628</strong></p>
  <p>Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13627 – Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13627</guid>
    <pubDate>Wed, 27 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13627</strong></p>
  <p>Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10946 – Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10946</guid>
    <pubDate>Wed, 27 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10946</strong></p>
  <p>Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10945 – Centreon before 19.10.7 exposes Session IDs in server responses.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10945</guid>
    <pubDate>Wed, 27 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10945</strong></p>
  <p>Centreon before 19.10.7 exposes Session IDs in server responses.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13252 – Centreon before 19.04.15 allows remote attackers to execute arbitrary OS command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13252</guid>
    <pubDate>Thu, 21 May 2020 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13252</strong></p>
  <p>Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19699 – There is Authenticated remote code execution in Centreon Infrastructure Monitori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19699</guid>
    <pubDate>Mon, 06 Apr 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19699</strong></p>
  <p>There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19487 – Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19487</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19487</strong></p>
  <p>Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19486 – Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19486</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19486</strong></p>
  <p>Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19484 – Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19484</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19484</strong></p>
  <p>Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17647 – An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17647</guid>
    <pubDate>Thu, 05 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17647</strong></p>
  <p>An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17646 – An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17646</guid>
    <pubDate>Thu, 05 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17646</strong></p>
  <p>An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17645 – An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17645</guid>
    <pubDate>Thu, 05 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17645</strong></p>
  <p>An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17642 – An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17642</guid>
    <pubDate>Thu, 05 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17642</strong></p>
  <p>An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17644 – An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17644</guid>
    <pubDate>Wed, 04 Mar 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17644</strong></p>
  <p>An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17643 – An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17643</guid>
    <pubDate>Wed, 04 Mar 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17643</strong></p>
  <p>An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9463 – Centreon 19.10 allows remote authenticated users to execute arbitrary OS command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9463</guid>
    <pubDate>Fri, 28 Feb 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9463</strong></p>
  <p>Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15299 – An issue was discovered in Centreon Web through 19.04.3. When a user changes his...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15299</guid>
    <pubDate>Mon, 24 Feb 2020 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15299</strong></p>
  <p>An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20327 – Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Soft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20327</guid>
    <pubDate>Thu, 16 Jan 2020 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20327</strong></p>
  <p>Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15300 – A problem was found in Centreon Web through 19.04.3. An authenticated SQL inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15300</guid>
    <pubDate>Wed, 27 Nov 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15300</strong></p>
  <p>A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15298 – A problem was found in Centreon Web through 19.04.3. An authenticated command in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15298</guid>
    <pubDate>Wed, 27 Nov 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15298</strong></p>
  <p>A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filter…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16195 – Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16195</guid>
    <pubDate>Tue, 26 Nov 2019 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16195</strong></p>
  <p>Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16406 – Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16406</guid>
    <pubDate>Thu, 21 Nov 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16406</strong></p>
  <p>Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16406">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
