vendor:
Centreon Web Appliance
by:
TheCyberGeek, enjloezz
7.2
CVSS
HIGH
Authenticated Remote Code Execution
78
CWE
Product Name: Centreon Web Appliance
Affected Version From: 18.10
Affected Version To: 19.04
Patch Exists: YES
Related CWE: CVE-2019-16405
CPE: a:centreon:centreon_web_appliance
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
Centreon Authenticated Macro Expression Location Setting Handler Code Execution
Authenticated Remote Code Execution on Centreon Web Appliances. Affected versions: =< 18.10, 19.04 By amending the Macros Expression's default directory to / we are able to execute system commands and obtain a shell as user Apache.
Mitigation:
Vendor verified: 09/17/2019 Vendor patched: 10/16/2019 Public disclosure: 10/18/2019