CVE-2019-16405
HIGH7.2EPSS 8.6%Improper Input Validation in Centreon Web
Published: 7/28/2021Modified: 11/8/2023
Description
Centreon Web 19.04.4 allows Remote Code Execution by an administrator who can modify Macro Expression location settings.
Affected packages (1)
- Packagist/centreon/centreonfrom 0, < 18.10.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
References (13)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-16405
- PATCHhttps://github.com/centreon/centreon
- WEBhttp://packetstormsecurity.com/files/155999/Centreon-19.04-Remote-Code-Execution.html
- WEBhttps://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10.html
- WEBhttps://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html
- WEBhttps://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10.html
- WEBhttps://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8.html
- WEBhttps://github.com/centreon/centreon/pull/7864
- WEBhttps://github.com/centreon/centreon/pull/7884
- WEBhttps://github.com/centreon/centreon/releases/tag/19.04.5
- WEBhttps://github.com/TheCyberGeek/CVE-2019-16405.rb
- WEBhttps://thecybergeek.co.uk/cves/2019/09/17/CVE-2019-16405-06.html
- WEBhttps://thecybergeek.co.uk/cves/2019/09/19/CVEs.html