User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
| Software | From | Fixed in |
|---|---|---|
| centreon / centreon_web | 23.10.0 | 23.10.26 |
| centreon / centreon_web | 24.04.0 | 24.04.16 |
| centreon / centreon_web | 24.10.0 | 24.10.9 |