Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
24.04.0 (semver) before 24.04.10
affected
24.10.0 (semver) before 24.10.4
affected
Description
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.
Problem types
CWE-863 Incorrect Authorization
Product status
24.04.0 (semver) before 24.04.10
24.10.0 (semver) before 24.10.4
Credits
Floerer from YesWeHack
References
thewatch.centreon.com/...572-centreon-web-high-severity-4460
github.com/centreon/centreon/releases