Vulnerabilities > Centreon

DATE CVE VULNERABILITY TITLE RISK
2020-05-27 CVE-2020-13628 Cross-Site Scripting vulnerability in Centreon products
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php.
network
centreon CWE-79
4.3
2020-05-27 CVE-2020-13627 Cross-Site Scripting vulnerability in Centreon products
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php.
network
centreon CWE-79
4.3
2020-05-27 CVE-2020-10946 Cross-Site Scripting vulnerability in Centreon products
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php.
network
centreon CWE-79
4.3
2020-05-27 CVE-2020-10945 Information Exposure vulnerability in Centreon
Centreon before 19.10.7 exposes Session IDs in server responses.
low complexity
centreon CWE-200
3.3
2020-05-21 CVE-2020-13252 OS Command Injection vulnerability in Centreon
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
network
low complexity
centreon CWE-78
critical
9.0
2020-04-06 CVE-2019-19699 Improper Privilege Management vulnerability in Centreon
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day.
network
low complexity
centreon CWE-269
critical
9.0
2020-03-20 CVE-2019-19487 OS Command Injection vulnerability in Centreon
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
network
low complexity
centreon CWE-78
6.5
2020-03-20 CVE-2019-19486 Path Traversal vulnerability in Centreon
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.
network
low complexity
centreon CWE-22
4.0
2020-03-20 CVE-2019-19484 Open Redirect vulnerability in Centreon
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
network
centreon CWE-601
5.8
2020-03-05 CVE-2019-17647 SQL Injection vulnerability in Centreon
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.
network
low complexity
centreon CWE-89
7.5