Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-66770
HistorySep 28, 2022 - 12:00 a.m.

Centreon SQL Injection Vulnerability (CNVD-2022-66770)

2022-09-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
centreon
sql injection
v20.10.18
escalation name
configuration
notifications
escalations
validation
attacker
sensitive data
sql commands

EPSS

0.001

Percentile

36.7%

Centreon (Merethis Centreon) is a set of open source system monitoring tools from the French company Centreon . A SQL injection vulnerability exists in Centreon v20.10.18, which stems from the esc_name (Escalation Name) parameter of its Configuration/Notifications/Escalations component Lack of validation of externally entered SQL statements. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.001

Percentile

36.7%