MEDIUM5.4
GHSA-r5mf-q76q-f2xq
Cross-site scripting in Centreon
Quick fix
GHSA-r5mf-q76q-f2xq — centreon/centreon: upgrade to the fixed version with the command below.
composer require centreon/centreon:^20.10.7Details
Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
Introduced in:
0Fixed in: 20.10.7Fix
composer require centreon/centreon:^20.10.7