Centreon vulnerable to SQL Injection
Critical severity
GitHub Reviewed
Published
Nov 2, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Package
Affected versions
< 22.10.0-beta1
Patched versions
22.10.0-beta1
Description
Published by the National Vulnerability Database
Nov 2, 2022
Published to the GitHub Advisory Database
Nov 2, 2022
Reviewed
Nov 4, 2022
Last updated
Feb 2, 2023
A SQL injection vulnerability in Centreon affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. Version 22.10.0-beta1 contains a patch for this issue.
References