CVE-2019-15298: Centreon Web
High severity, CVSS 8.8. EPSS: 26.6% chance of exploitation in the next 30 days.
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.
Affected products
- Centreon Centreon Web: from 2.8.1, before 2.8.30 (fixed in 2.8.30); from 18.10.0, before 18.10.8 (fixed in 18.10.8); from 19.04.0, before 19.04.5 (fixed in 19.04.5); from 19.10.0, before 19.10.2 (fixed in 19.10.2)
Published 2019-11-27. Last modified 2026-06-17.