Vulnerabilities (CVE)

Filtered by vendor Centreon Subscribe
Filtered by product Centreon Web
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26804 1 Centreon 1 Centreon Web 2021-05-12 4.0 MEDIUM 6.5 MEDIUM
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
CVE-2019-17108 1 Centreon 1 Centreon Web 2019-10-15 4.3 MEDIUM 6.1 MEDIUM
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
CVE-2019-17105 1 Centreon 1 Centreon Web 2019-10-15 5.0 MEDIUM 5.3 MEDIUM
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
CVE-2019-17106 1 Centreon 1 Centreon Web 2019-10-10 4.0 MEDIUM 6.5 MEDIUM
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
CVE-2018-11588 1 Centreon 2 Centreon, Centreon Web 2018-08-28 3.5 LOW 5.4 MEDIUM
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.