Description
User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
24.10.0 before 24.10.9
24.04.0 before 24.04.16
23.10.0 before 23.10.26
Credits
SpawnZii for YesWeHack
References
github.com/centreon/centreon/releases
thewatch.centreon.com/...web-all-versions-high-severity-4901