Description
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18410.
Published: 2023-03-29
Score: 8.8 High
EPSS: 59.0% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-45502 This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18410.
History

Fri, 14 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Centreon Centreon
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2025-02-14T16:33:23.700Z

Reserved: 2022-10-03T00:00:00.000Z

Link: CVE-2022-42428

cve-icon Vulnrichment

Updated: 2024-08-03T13:10:40.468Z

cve-icon NVD

Status : Modified

Published: 2023-03-29T19:15:17.503

Modified: 2024-11-21T07:24:57.267

Link: CVE-2022-42428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses