CVE-2019-15298
Estado: ModificadaAlta (8.8)—
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 27%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html
- https://github.com/centreon/centreon/pull/8023
- https://www.certilience.fr/2019/08/CVE-2019-15298-vulnerabilit%C3%A9-centreon-command-injection
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html
- https://github.com/centreon/centreon/pull/8023
- https://www.certilience.fr/2019/08/CVE-2019-15298-vulnerabilit%C3%A9-centreon-command-injection
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-15298",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-11-27T14:15:11.280",
"references": [
{
"url": "https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/centreon/centreon/pull/8023",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.certilience.fr/2019/08/CVE-2019-15298-vulnerabilit%C3%A9-centreon-command-injection",
"tags": [
"Not Applicable"
],
"source": "cve@mitre.org"
},
{
"url": "https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/centreon/centreon/pull/8023",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.certilience.fr/2019/08/CVE-2019-15298-vulnerabilit%C3%A9-centreon-command-injection",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly."
},
{
"lang": "es",
"value": "Se encontró un problema en Centreon Web versiones hasta 19.04.3. Una inyección de comando autenticada está presente en la página include/configuration/configObject/traps-mibs/formMibs.php. Esta página es llamada desde la interfaz de administración de Centreon. Esta es la funcionalidad de administración mibs que contiene un formulario de archivo. Al momento del envío de un archivo, el parámetro mnftr es enviado a la página y no es filtrado apropiadamente. Esto permite inyectar comandos de Linux directamente."
}
],
"lastModified": "2026-06-17T02:20:03.227",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3C5FCB6-6FA6-4C9D-A5B2-118313A53E74",
"versionEndExcluding": "2.8.30",
"versionStartIncluding": "2.8.1"
},
{
"criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2BACAD9-E250-471E-95AC-C2BDC88C6251",
"versionEndExcluding": "18.10.8",
"versionStartIncluding": "18.10.0"
},
{
"criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4F95794-5463-4FD2-BFD4-083B10326460",
"versionEndExcluding": "19.04.5",
"versionStartIncluding": "19.04.0"
},
{
"criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74D8CBF6-AC59-4667-8243-C62C3A5FB2F4",
"versionEndExcluding": "19.10.2",
"versionStartIncluding": "19.10.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}