CVE-2019-15298

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
27/11/2019
Last modified:
24/08/2020

Description

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 2.8.1 (including) 2.8.30 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 18.10.0 (including) 18.10.8 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 19.04.0 (including) 19.04.5 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 19.10.0 (including) 19.10.2 (excluding)