{"id":"CVE-2018-19312","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-19312","summary":"Centreon SQL Injection","details":"Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.","published":"2022-05-14T00:55:28Z","modified":"2023-11-08T04:00:07.571649Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"centreon/centreon","fixedVersion":"18.10.0"},{"ecosystem":"Packagist","name":"centreon/centreon","fixedVersion":"2.8.24"}],"fix":{"url":"https://github.com/centreon/centreon-archived/pull/6257","label":"centreon/centreon-archived#6257"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19312"},{"type":"WEB","url":"https://github.com/centreon/centreon-archived/pull/6257"},{"type":"WEB","url":"https://github.com/centreon/centreon-archived/pull/6628"},{"type":"WEB","url":"https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.0.html"},{"type":"WEB","url":"https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html"},{"type":"WEB","url":"http://www.roothc.com.br/1349-2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:00:07.571649Z"}}