Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these details are obtained from third party information.
Software | From | Fixed in |
---|---|---|
centreon / centreon | - | 1.4.2.3.x |
centreon / centreon | 1.4 | 1.4.x |
centreon / centreon | 1.4.1 | 1.4.1.x |
centreon / centreon | 1.4.2 | 1.4.2.x |
centreon / centreon | 1.4.2.1 | 1.4.2.1.x |
centreon / centreon | 1.4.2.2 | 1.4.2.2.x |