CVE-2024-45754

EUVD-2024-41583
An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
centreoncentreon
22.10.0 ≤
𝑥
< 22.10.11
ADP
centreoncentreon
23.10.0 ≤
𝑥
< 23.10.8
ADP
centreoncentreon
24.04.0 ≤
𝑥
< 24.04.3
ADP
centreoncentreon
23.04.0 ≤
𝑥
< 23.04.11
ADP