Centreon Web Application OS Command Injection

Strike ID:
E23-7qua1
CVSS:
8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2019

Description

The strike exploits a Command Injection Vulnerability in Centreon Web Application. This vulnerability is due to incorrect input validation on the mnftr parameter in mibs management form. A remote, authenticated attacker could exploit this vulnerability by sending a maliciously crafted request to the target server. Successful exploitation could result in the execution of arbitrary code.

CVE