- Description
- An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.
- Source
- cve@mitre.org
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-89
- Hype score
- Not currently trending
Centreon の SQLi 脆弱性 CVE-2024-55573/53923 が FIX:直ちにアップデートを! https://t.co/mYHTiWLzu5 Centreon の深刻な SQL インジェクション脆弱性が FIX しました。CVSS 値も高いので、ご利用のチームは、ご注意ください。 #Centreon #CVE202453923 #CVE202455573 #Monitoring #OpenSource… https://t.co/b9ycbF4peN
@iototsecnews
5 Feb 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Centreon has released urgent updates due to critical SQL injection vulnerabilities, CVE-2024-55573 and CVE-2024-53923, both scoring 9.1. Attackers can gain control over systems. ⚠️ #Centreon #SQLVulnerability #France link: https://t.co/0xK0j3WQFs https://t.co/37U2UveBAN
@TweetThreatNews
28 Jan 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-55573, -53923: SQLi in Centreon, 9.1 rating 🔥 The vulnerabilities allow an attacker with high privileges to perform SQL injection into a form for uploading media. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/FSCJTS46JZ #cybersecurity #vulnerability_map ht
@Netlas_io
28 Jan 2025
1184 Impressions
2 Retweets
9 Likes
7 Bookmarks
0 Replies
0 Quotes
CVE-2024-55573 An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high pr… https://t.co/eV0770Sz2N
@CVEnew
24 Jan 2025
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-55573: CRITICAL] Critical security flaw in Centreon versions 24.10.x, 24.04.x, 23.10.x, and 23.04.x allows SQL injection through creating virtual metrics, enabling privilege escalation. Update now!#cybersecurity,#vulnerability https://t.co/3FNhmTFppA https://t.co/r57RFh
@CveFindCom
23 Jan 2025
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes