CVE-2019-15299
24.02.2020, 13:15
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.Enginsight
Vendor | Product | Version |
---|---|---|
centreon | centreon_web | 𝑥 ≤ 19.04.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References