Page 3 of 21 results (0.002 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

25 Jun 2018 — Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php. Centreon 3.4.6 incluyendo Centreon Web 2.8.23 es vulnerable a que un usuario autenticado inyecte una carga útil en la descripción del nombre de usuario o del comando, lo que resulta en Cross-Site Scripting (XSS) persisten... • https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •