Component: centreon-anomaly-detection
List of vulnerabilities: 1
Description: SQL injection via raw access-group list in service ACL filter
Reference: N/A
CVSS: 8.8
Severity: High
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Anomaly Detection on Central Server:
Component: centreon-autodiscovery
List of vulnerabilities: 1
Description: SQL injection and unsafe exec() in rule management
Reference: N/A
CVSS: 8.8
Severity: High
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Autodiscovery on Central Server:
Component: centreon-bam
List of vulnerabilities: 1
Description: SQL injection, XSS, info disclosure & command exec in legacy PHP files
Reference: N/A
CVSS: 8.8
Severity: High
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Bam on Central Server:
Component: centreon-mbi
List of vulnerabilities: 1
Description: SQL injection via string concatenation across legacy PHP files (mbi)
Reference: N/A
CVSS: 8.8
Severity: High
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Mbi on Central Server:
Component: centreon-open-tickets
List of vulnerabilities: 2
Description: SQL injection via string concatenation across legacy PHP files
Reference: N/A
CVSS: 8.8
Severity: High
Description: Reflected Cross-Site Scripting (XSS) in Open Tickets Widget Toolbar
Reference: N/A
CVSS: 6.8
Severity: Medium
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Open Tickets on Central Server:
Component: centreon-pp-manager
List of vulnerabilities: 1
Description: SQL injection via string concatenation in installation classes
Reference: N/A
CVSS: 8.8
Severity: High
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Pp Manager on Central Server:
Component: centreon-web
List of vulnerabilities: 13
Description: SQL injection via string concatenation in legacy PHP files
Reference: N/A
CVSS: 8.8
Severity: High
Description: Misc legacy (SQLi + XSS in assorted legacy classes)
Reference: N/A
CVSS: 7
Severity: High
Description: CLAPI (SQLi in command-line API classes)
Reference: N/A
CVSS: 7
Severity: High
Description: Knowledge / Wiki (SQLi + disabled TLS in MediaWiki integration)
Reference: N/A
CVSS: 7
Severity: High
Description: Pollers / Broker (SQLi + unserialize RCE in engine/broker/remote config)
Reference: N/A
CVSS: 7
Severity: High
Description: Downtime / Acknowledgement (SQLi in RT downtime & ack)
Reference: N/A
CVSS: 7
Severity: High
Description: Hosts (SQLi in host & hostgroup data access)
Reference: N/A
CVSS: 7
Severity: High
Description: Services (SQLi + XSS in service / servicegroup screens)
Reference: N/A
CVSS: 7
Severity: High
Description: Timeperiods (SQLi in timeperiod config & rendering)
Reference: N/A
CVSS: 7
Severity: High
Description: Users / Sessions / Auth (SQLi in auth & session)
Reference: N/A
CVSS: 7
Severity: High
Description: Legacy API classes (SQLi in `www/api/class`)
Reference: N/A
CVSS: 7
Severity: High
Description: Common helpers / Forms (SQLi + XSS + RCE + TLS in shared utilities)
Reference: N/A
CVSS: 7
Severity: High
Description: ORM / DB layer (SQLi in generic data-access plumbing)
Reference: N/A
CVSS: 7
Severity: High
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server:
