{"api_version":"1","generated_at":"2026-07-23T15:28:13+00:00","cve":"CVE-2018-11589","urls":{"html":"https://cve.report/CVE-2018-11589","api":"https://cve.report/api/cve/CVE-2018-11589.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-11589","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-11589"},"summary":{"title":"CVE-2018-11589","description":"Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-06-25 18:29:00","updated_at":"2018-08-28 17:14:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://github.com/centreon/centreon/pull/6257","name":"https://github.com/centreon/centreon/pull/6257","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix(sec): Fix SQL Injection in Virtual Metrics by leoncx · Pull Request #6257 · centreon/centreon · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/centreon/centreon/pull/6250","name":"https://github.com/centreon/centreon/pull/6250","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix(sec): Fix SQL injection in dashboard by leoncx · Pull Request #6250 · centreon/centreon · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/centreon/centreon/releases","name":"https://github.com/centreon/centreon/releases","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Releases · centreon/centreon · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/centreon/centreon/pull/6256","name":"https://github.com/centreon/centreon/pull/6256","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix(sec): Fix SQL injection in Curve template by leoncx · Pull Request #6256 · centreon/centreon · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/centreon/centreon/pull/6255","name":"https://github.com/centreon/centreon/pull/6255","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix(sec): Fix SQL Injection in administration logs by leoncx · Pull Request #6255 · centreon/centreon · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/centreon/centreon/pull/6251","name":"https://github.com/centreon/centreon/pull/6251","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix(sec): Fix SQL injection on graphs by leoncx · Pull Request #6251 · centreon/centreon · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html","name":"https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"Centreon Web 2.8.24 — Centreon 19.04.0 documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-11589","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11589","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"11589","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"centreon","cpe5":"centreon","cpe6":"3.4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"11589","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"centreon","cpe5":"centreon","cpe6":"3.4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"11589","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"centreon","cpe5":"centreon_web","cpe6":"2.8.23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"11589","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"centreon","cpe5":"centreon_web","cpe6":"2.8.23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-11589","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/centreon/centreon/pull/6250","refsource":"CONFIRM","url":"https://github.com/centreon/centreon/pull/6250"},{"name":"https://github.com/centreon/centreon/pull/6257","refsource":"CONFIRM","url":"https://github.com/centreon/centreon/pull/6257"},{"name":"https://github.com/centreon/centreon/pull/6251","refsource":"CONFIRM","url":"https://github.com/centreon/centreon/pull/6251"},{"name":"https://github.com/centreon/centreon/pull/6256","refsource":"CONFIRM","url":"https://github.com/centreon/centreon/pull/6256"},{"name":"https://github.com/centreon/centreon/releases","refsource":"CONFIRM","url":"https://github.com/centreon/centreon/releases"},{"name":"https://github.com/centreon/centreon/pull/6255","refsource":"CONFIRM","url":"https://github.com/centreon/centreon/pull/6255"},{"name":"https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html","refsource":"CONFIRM","url":"https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html"}]}},"nvd":{"publishedDate":"2018-06-25 18:29:00","lastModifiedDate":"2018-08-28 17:14:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:centreon:centreon_web:2.8.23:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:centreon:centreon:3.4.6:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"11589","Ordinal":"128066","Title":"CVE-2018-11589","CVE":"CVE-2018-11589","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"11589","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"11589","Ordinal":"2","NoteData":"2018-06-25","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"11589","Ordinal":"3","NoteData":"2018-06-25","Type":"Other","Title":"Modified"}]}}}