Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
| Software | From | Fixed in |
|---|---|---|
| centreon / centreon_web | 19.10.18 | 19.10.18.x |
| centreon / centreon_web | 20.04.8 | 20.04.8.x |
| centreon / centreon_web | 20.10.2 | 20.10.2.x |