An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only accessible to authenticated users with high-privileged access.
History

Tue, 26 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Centreon
Centreon centreon
CPEs cpe:2.3:a:centreon:centreon:-:*:*:*:*:*:*:*
Vendors & Products Centreon
Centreon centreon
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 25 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only accessible to authenticated users with high-privileged access.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-25T00:00:00

Updated: 2024-11-26T15:15:00.564Z

Reserved: 2024-09-06T00:00:00

Link: CVE-2024-45755

cve-icon Vulnrichment

Updated: 2024-11-26T15:14:42.788Z

cve-icon NVD

Status : Received

Published: 2024-11-25T17:15:12.293

Modified: 2024-11-26T16:15:15.597

Link: CVE-2024-45755

cve-icon Redhat

No data.