VDB
Sign up
MEDIUM5.4

GHSA-8vh5-j6xj-5953

Centreon XSS Vulnerability

Quick fix

GHSA-8vh5-j6xj-5953 — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^18.10.0

Details

Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the `main.php?p=20201` URI, as demonstrated by the "Monitoring > Status Details > Services" screen.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 18.0.0Fixed in: 18.10.0
Fixcomposer require centreon/centreon:^18.10.0

References