Back to search
CVE-2018-11588
Published: Jun 25, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/centreon/centreon/releases
x_refsource_CONFIRM
https://github.com/centreon/centreon/pull/6260
x_refsource_CONFIRM
https://github.com/centreon/centreon/pull/6259
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now