VDB
Sign up
CRITICAL9.8

GHSA-j5wx-jvw3-j363

Centreon vulnerable to SQL Injection

Quick fix

GHSA-j5wx-jvw3-j363 — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^22.10.0-beta1

Details

A SQL injection vulnerability in Centreon affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. Version 22.10.0-beta1 contains a patch for this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 0Fixed in: 22.10.0-beta1
Fixcomposer require centreon/centreon:^22.10.0-beta1

References