CVE-2024-32501

EUVD-2024-30303
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
centreoncentreon_web
22.10.0 ≤
𝑥
< 22.10.23
centreoncentreon_web
23.04.0 ≤
𝑥
< 23.04.19
centreoncentreon_web
23.10.0 ≤
𝑥
< 23.10.13
centreoncentreon_web
24.04.0 ≤
𝑥
< 24.04.3
𝑥
= Vulnerable software versions