VDB
Sign up
CRITICAL9.8

GHSA-wgjx-hm34-qgf7

SQL injection in Centreon

Quick fix

GHSA-wgjx-hm34-qgf7 — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^18.10.8

Details

SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 0Fixed in: 18.10.8
Fixcomposer require centreon/centreon:^18.10.8
Packagist/centreon/centreon
Introduced in: 19.0.0Fixed in: 19.04.5
Fixcomposer require centreon/centreon:^19.04.5

References