CVE-2019-15300: Centreon Web

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.

Affected products

  • Centreon Centreon Web: from 2.8.1, before 2.8.30 (fixed in 2.8.30); from 19.04.0, before 19.04.5 (fixed in 19.04.5); from 19.10.0, before 19.10.2 (fixed in 19.10.2)

Published 2019-11-27. Last modified 2026-06-17.