CVE-2018-19312: Centreon

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.

Affected products

  • Centreon Centreon: from 3.4.0, up to and including 3.4.9

Published 2018-11-16. Last modified 2026-06-17.