web
by Centreon
Source repositories
CVEs (57)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26804 | Med | 0.42 | 6.5 | 0.01 | May 4, 2021 | Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application. | ||
| CVE-2025-10023 | Med | 0.40 | 6.2 | 0.00 | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before… | ||
| CVE-2025-12519 | Med | 0.34 | 5.3 | 0.00 | Jan 5, 2026 | Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue… | ||
| CVE-2025-4649 | Med | 0.32 | 4.9 | 0.00 | May 13, 2025 | Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects… | ||
| CVE-2019-17105 | Med | 0.28 | 5.3 | 0.02 | Oct 8, 2019 | The token generator in index.php in Centreon Web before 2.8.27 is predictable. | ||
| CVE-2019-15298 | Hig | 0.02 | 8.8 | 0.27 | Nov 27, 2019 | A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that… | ||
| CVE-2019-15299 | Hig | 0.00 | 8.8 | 0.02 | Feb 24, 2020 | An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication. | ||
| CVE-2019-15300 | Hig | 0.00 | 8.8 | 0.02 | Nov 27, 2019 | A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query. | ||
| CVE-2019-17108 | Med | 0.00 | 6.1 | 0.01 | Oct 8, 2019 | Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user. | ||
| CVE-2019-17106 | Med | 0.00 | 6.5 | 0.01 | Oct 8, 2019 | In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components. | ||
| CVE-2018-21023 | Hig | 0.00 | 8.8 | 0.03 | Oct 8, 2019 | getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter. | ||
| CVE-2018-21022 | Hig | 0.00 | 8.8 | 0.02 | Oct 8, 2019 | makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter. | ||
| CVE-2018-21021 | Hig | 0.00 | 8.8 | 0.02 | Oct 8, 2019 | img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter. | ||
| CVE-2018-21020 | Hig | 0.00 | 7.5 | 0.02 | Oct 8, 2019 | In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place. | ||
| CVE-2018-11589 | Cri | 0.00 | 9.8 | 0.02 | Jun 25, 2018 | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in… | ||
| CVE-2018-11588 | Med | 0.00 | 5.4 | 0.01 | Jun 25, 2018 | Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArgu… | ||
| CVE-2018-11587 | Cri | 0.00 | 9.8 | 0.04 | Jun 25, 2018 | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php. |
- risk 0.42cvss 6.5epss 0.01
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
- risk 0.40cvss 6.2epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before…
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue…
- risk 0.32cvss 4.9epss 0.00
Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects…
- risk 0.28cvss 5.3epss 0.02
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
- risk 0.02cvss 8.8epss 0.27
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that…
- risk 0.00cvss 8.8epss 0.02
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
- risk 0.00cvss 8.8epss 0.02
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.
- risk 0.00cvss 6.1epss 0.01
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
- risk 0.00cvss 6.5epss 0.01
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
- risk 0.00cvss 8.8epss 0.03
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
- risk 0.00cvss 8.8epss 0.02
makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.
- risk 0.00cvss 8.8epss 0.02
img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.
- risk 0.00cvss 7.5epss 0.02
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.
- risk 0.00cvss 9.8epss 0.02
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in…
- risk 0.00cvss 5.4epss 0.01
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArgu…
- risk 0.00cvss 9.8epss 0.04
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
Page 3 of 3