Skip to main content
security bulletin

CVE-2024-55573 - Centreon Web - Critical severity

  • January 13, 2025
  • 1 reply
  • 985 views

lpinsivy
Centreonian
Forum|alt.badge.img+21

Publication date: January 3rd, 2025

Component: centreon-web (on central server).

Feature: Virtual metrics settings

 

Description: SQLi in the form used to create virtual metrics in centreon-web, only accessible to authenticated users with high privilege access and rights to create a virtual metric.

 

ReferenceCVE-2024-55573

CVSS9.1 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 

SeverityCRITICAL

 

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Central server:

These versions include cumulative fixes from prior updates.

 

Reporter: SpawnZii for YesWeHack

SubmissionNovember 25, 2024
 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.

1 reply

dagabard
Forum|alt.badge.img+5
  • Steward *
  • 34 replies
  • February 6, 2025

just be psychopath to do this ...