← All CVEs

CVE-2019-15298

high · 8.8

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.

8.8
CVSS
26.6%
EPSS (exploit prob.)
98th
EPSS percentile
2019-11-27
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
centreoncentreon_web>= 2.8.1, < 2.8.30
centreoncentreon_web>= 18.10.0, < 18.10.8
centreoncentreon_web>= 19.04.0, < 19.04.5
centreoncentreon_web>= 19.10.0, < 19.10.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-15298