CVE-2024-5725
Last modified
CVE-2024-5725 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. EPSS estimates a 47.65% chance of exploitation in the next 30 days.
Description
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-22683.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Centreon | Centreon Web | < 22.10.23 |
| Centreon | Centreon Web | >= 23.04.0, < 23.04.19 |
| Centreon | Centreon Web | >= 23.10.0, < 23.10.13 |
| Centreon | Centreon Web | >= 24.04.0, < 24.04.3 |
References
- https://www.zerodayinitiative.com/advisories/ZDI-24-597/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5725?
How severe is CVE-2024-5725?
How do I fix CVE-2024-5725?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-57238Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable…7.3
- CVE-2024-5724The Photo Video Gallery Master plugin for WordPress is vulne…8.8
- CVE-2024-57240A Cross-Site Scripting (XSS) vulnerability in the Rendering …5.4
- CVE-2024-57241Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. I…6.5
- CVE-2024-57248Directory Traversal in File Upload in Gleamtech FileVista 9.…6.3
- CVE-2024-57249Incorrect Access Control in the Preview Function of Gleamtec…6.5
- CVE-2024-57252OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (…4.3
- CVE-2024-57254An integer overflow in sqfs_inode_size in Das U-Boot before …6.8
- CVE-2024-57255An integer overflow in sqfs_resolve_symlink in Das U-Boot be…6.8
- CVE-2024-57256An integer overflow in ext4fs_read_symlink in Das U-Boot bef…6.8
- CVE-2024-57257A stack consumption issue in sqfs_size in Das U-Boot before …2.4
- CVE-2024-57258Integer overflows in memory allocation in Das U-Boot before …7.8
Are you affected by CVE-2024-5725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
