CVE-2018-11589
Last modified
CVE-2018-11589 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Centreon | Centreon | 3.4.6 |
| Centreon | Centreon Web | 2.8.23 |
References
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.htmlRelease Notes, Vendor Advisory
- https://github.com/centreon/centreon/pull/6250Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6251Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6255Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6256Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6257Patch, Third Party Advisory
- https://github.com/centreon/centreon/releasesThird Party Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.htmlRelease Notes, Vendor Advisory
- https://github.com/centreon/centreon/pull/6250Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6251Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6255Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6256Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/6257Patch, Third Party Advisory
- https://github.com/centreon/centreon/releasesThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11589?
How severe is CVE-2018-11589?
How do I fix CVE-2018-11589?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11580An issue was discovered in mass-pages-posts-creator.php in t…
- CVE-2018-11581Cross-site scripting (XSS) vulnerability on Brother HL serie…
- CVE-2018-11583SeaCMS 6.61 has stored XSS in admin_collect.php via the site…
- CVE-2018-11586XML external entity (XXE) vulnerability in api/rest/status i…
- CVE-2018-11587There is Remote Code Execution in Centreon 3.4.6 including C…
- CVE-2018-11588Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable t…
- CVE-2018-1159Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to …
- CVE-2018-11590Espruino before 1.99 allows attackers to cause a denial of s…
- CVE-2018-11591Espruino before 1.98 allows attackers to cause a denial of s…
- CVE-2018-11592Espruino before 1.98 allows attackers to cause a denial of s…
- CVE-2018-11593Espruino before 1.99 allows attackers to cause a denial of s…
- CVE-2018-11594Espruino before 1.99 allows attackers to cause a denial of s…
Are you affected by CVE-2018-11589?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
