CVE-2024-23119: Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability
8.8
CVSS Score
3.0
Basic Information
CVE ID
GHSA ID
EPSS Score
0.96917%
CWE
Published
4/2/2024
Updated
4/2/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| centreon/centreon | composer | < 22.10.15 | 22.10.15 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
- The vulnerability title and description explicitly name insertGraphTemplate as the vulnerable function.
- CWE-89 (SQL Injection) aligns with the described lack of input validation before SQL query construction.
- While the provided commit diff shows template escaping fixes in listHost.ihtml, this appears to be a secondary hardening measure. The primary vulnerability resides in the backend SQL handling of insertGraphTemplate, as confirmed by:
- ZDI's advisory explicitly referencing the function
- CVSS vector showing authentication requirement (PR:L)
- Vulnerability severity tied to direct SQL query manipulation
- The function name follows Centreon's pattern for configuration object handlers (matching the affected component 'graphTemplate').