Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/centreon/centreon/pull/7876 | third party advisory patch |
https://github.com/centreon/centreon/pull/7877 | third party advisory patch |
https://github.com/centreon/centreon/releases/tag/19.04.5 | third party advisory release notes |
https://github.com/centreon/centreon/releases/tag/2.8.30 | third party advisory release notes |
https://github.com/centreon/centreon/releases/tag/18.10.8 | third party advisory release notes |