Discover the SQL Injection vulnerability in Centreon versions before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. Learn the impact, affected systems, exploitation method, and mitigation steps.
A vulnerability has been found in Centreon versions prior to 2.8.30, 18.10.8, 19.04.5, and 19.10.2. An SQL Injection exploit can be performed by utilizing the instance parameter in the include/monitoring/status/Hosts/xml/hostXML.php file.
Understanding CVE-2019-17647
This CVE identifies a SQL Injection vulnerability in Centreon versions before specific releases.
What is CVE-2019-17647?
CVE-2019-17647 is a security vulnerability in Centreon that allows attackers to execute SQL Injection through a specific parameter in a file.
The Impact of CVE-2019-17647
This vulnerability can lead to unauthorized access to the database, data manipulation, and potentially complete system compromise.
Technical Details of CVE-2019-17647
This section provides detailed technical information about the CVE.
Vulnerability Description
The vulnerability exists in Centreon versions prior to 2.8.30, 18.10.8, 19.04.5, and 19.10.2, allowing SQL Injection via a specific parameter in a particular file.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability by manipulating the 'instance' parameter in the hostXML.php file to inject malicious SQL queries.
Mitigation and Prevention
Protect your systems from CVE-2019-17647 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates