An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access.

Project Subscriptions

Vendors Products
Centreon Subscribe
Centreon Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 25 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Centreon
Centreon centreon
Weaknesses CWE-89
CPEs cpe:2.3:a:centreon:centreon:-:*:*:*:*:*:*:*
Vendors & Products Centreon
Centreon centreon
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-25T18:26:43.991Z

Reserved: 2024-09-06T00:00:00

Link: CVE-2024-45756

cve-icon Vulnrichment

Updated: 2024-11-25T18:19:06.759Z

cve-icon NVD

Status : Received

Published: 2024-11-25T18:15:12.907

Modified: 2024-11-25T19:15:10.673

Link: CVE-2024-45756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses