CVE-2024-32501

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/08/2024
Last modified:
09/05/2025

Description

A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 22.10.0 (including) 22.10.23 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 23.04.0 (including) 23.04.19 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 23.10.0 (including) 23.10.13 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 24.04.0 (including) 24.04.3 (excluding)