HIGH8.8
GHSA-79hg-357g-rrgv
Centreon SQL Injection
Quick fix
GHSA-79hg-357g-rrgv — centreon/centreon: upgrade to the fixed version with the command below.
composer require centreon/centreon:^18.10.0Details
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
Introduced in:
18.0.0Fixed in: 18.10.0Fix
composer require centreon/centreon:^18.10.0Packagist/centreon/centreon
Introduced in:
0Fixed in: 2.8.28Fix
composer require centreon/centreon:^2.8.28References
- https://nvd.nist.gov/vuln/detail/CVE-2018-19271[ADVISORY]
- https://github.com/centreon/centreon-archived/pull/6625[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.28.html[WEB]
- http://www.rootlabs.com.br/authenticated-sql-injection-in-centreon-3-4-x[WEB]