Vulnerabilities > Centreon
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-26 | CVE-2021-27676 | Cross-site Scripting vulnerability in Centreon 20.10.2 Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. | 5.4 |
2021-05-04 | CVE-2021-26804 | Incorrect Default Permissions vulnerability in Centreon web 19.10.18/20.04.8/20.10.2 Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application. | 6.5 |
2021-04-15 | CVE-2021-28055 | Use of Insufficiently Random Values vulnerability in Centreon 20.10.0 An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. | 6.5 |
2021-02-15 | CVE-2020-22425 | SQL Injection vulnerability in Centreon 19.10 Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution. | 8.8 |
2020-05-27 | CVE-2020-13628 | Cross-site Scripting vulnerability in Centreon products Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. | 6.1 |
2020-05-27 | CVE-2020-13627 | Cross-site Scripting vulnerability in Centreon products Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. | 6.1 |
2020-05-27 | CVE-2020-10946 | Cross-site Scripting vulnerability in Centreon products Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. | 6.1 |
2020-05-27 | CVE-2020-10945 | Information Exposure vulnerability in Centreon and Widget-Host-Monitoring Centreon before 19.10.7 exposes Session IDs in server responses. | 4.3 |
2020-05-21 | CVE-2020-13252 | OS Command Injection vulnerability in Centreon Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page. | 8.8 |
2020-04-06 | CVE-2019-19699 | Improper Privilege Management vulnerability in Centreon There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. | 7.2 |