Vulnerabilities
Vulnerable Software
Centreon:  >> Centreon  >> 19.10.0  Security Vulnerabilities
Centreon before 19.10.7 exposes Session IDs in server responses.
CVSS Score
4.3
EPSS Score
0.0
Published
2020-05-27
An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-05
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.
CVSS Score
9.8
EPSS Score
0.001
Published
2020-03-05
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.
CVSS Score
8.8
EPSS Score
0.003
Published
2020-03-05
An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-05
An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.
CVSS Score
7.5
EPSS Score
0.0
Published
2020-03-04
An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-04


Contact Us

Shodan ® - All rights reserved