CVE-2022-40043

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in packagist/centreon/centreon

Identifiers

CVE-2022-40043

Package Slug

packagist/centreon/centreon

Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Description

Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.

Affected Versions

Version 20.10.18

Solution

Upgrade to version 21.04.0 or above.

Last Modified

2022-09-29

source