VYPR
Unrated severityNVD Advisory· Published Aug 23, 2024· Updated Aug 27, 2024

CVE-2024-32501

CVE-2024-32501

Description

A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Centreon Web versions before 24.04.3, 23.10.13, 23.04.19, and 22.10.23 are vulnerable to SQL injection in the updateServiceHost function.

Vulnerability

A SQL injection vulnerability exists in the updateServiceHost functionality of Centreon Web. All on-premise versions prior to the fixes are affected: Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23 [2]. The vulnerability allows an attacker to inject arbitrary SQL queries via crafted input to the updateServiceHost endpoint.

Exploitation

An attacker must have authenticated access to the Centreon Web interface. With network access and valid credentials, the attacker can craft malicious SQL statements in the parameters of the updateServiceHost request. This can be done without special privileges beyond a standard user account [2]. The attack does not require user interaction beyond the initial login.

Impact

Successful exploitation enables the attacker to execute arbitrary SQL commands on the underlying database. This can lead to unauthorized data access, modification, or deletion, potentially compromising the entire Centreon platform. The impact is considered severe, particularly if the Centreon instance is exposed to the internet [2].

Mitigation

The vulnerability is fixed in Centreon Web versions 24.04.3, 23.10.13, 23.04.19, and 22.10.23 [2]. Users running unsupported versions should upgrade to the latest supported release (e.g., 24.04). Centreon Cloud platforms have been automatically updated. No workaround is available; applying the patch is the only mitigation [2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Centreon/Centreon Webcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: == 24.04.x (< 24.04.3) OR == 23.10.x (< 23.10.13) OR == 23.04.x (< 23.04.19) OR == 22.10.x (< 22.10.23)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.