CVE-2020-13627
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.
Una vulnerabilidad de tipo cross-site scripting (XSS) permite a atacantes remotos inyectar scripts web o HTML arbitrario por medio del parĂ¡metro widgetId en el archivo host-monitoring/src/toolbar.php. Esta vulnerabilidad es corregida en las versiones 1.6.4, 18.10.3, 19.04.3 y 19.0.1 del Centreon host-monitoring widget; las versiones 1.6.4, 18.10.5, 19.04.3, 19.10.2 del Centreon service-monitoring widget; y las versiones 1.0.3, 18.10.1, 19.04.1, 19.10.1 del Centreon tactical-overview widget.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-27 CVE Reserved
- 2020-05-27 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://sysdream.com/news/lab/2020-05-13-cve-2020-10946-several-cross-site-scripting-xss-vulnerabilities-in-centreon | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Centreon Search vendor "Centreon" | Centreon Host-monitoring Widget Search vendor "Centreon" for product "Centreon Host-monitoring Widget" | < 1.6.4 Search vendor "Centreon" for product "Centreon Host-monitoring Widget" and version " < 1.6.4" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Host-monitoring Widget Search vendor "Centreon" for product "Centreon Host-monitoring Widget" | >= 18.10.0 < 18.10.3 Search vendor "Centreon" for product "Centreon Host-monitoring Widget" and version " >= 18.10.0 < 18.10.3" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Host-monitoring Widget Search vendor "Centreon" for product "Centreon Host-monitoring Widget" | >= 19.0.0 < 19.0.1 Search vendor "Centreon" for product "Centreon Host-monitoring Widget" and version " >= 19.0.0 < 19.0.1" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Host-monitoring Widget Search vendor "Centreon" for product "Centreon Host-monitoring Widget" | >= 19.04.0 < 19.04.3 Search vendor "Centreon" for product "Centreon Host-monitoring Widget" and version " >= 19.04.0 < 19.04.3" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Tactical-overview Widget Search vendor "Centreon" for product "Centreon Tactical-overview Widget" | < 1.0.3 Search vendor "Centreon" for product "Centreon Tactical-overview Widget" and version " < 1.0.3" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Tactical-overview Widget Search vendor "Centreon" for product "Centreon Tactical-overview Widget" | >= 18.10.0 < 18.10.1 Search vendor "Centreon" for product "Centreon Tactical-overview Widget" and version " >= 18.10.0 < 18.10.1" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Tactical-overview Widget Search vendor "Centreon" for product "Centreon Tactical-overview Widget" | >= 19.04.0 < 19.04.1 Search vendor "Centreon" for product "Centreon Tactical-overview Widget" and version " >= 19.04.0 < 19.04.1" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Tactical-overview Widget Search vendor "Centreon" for product "Centreon Tactical-overview Widget" | >= 19.10.0 < 19.10.1 Search vendor "Centreon" for product "Centreon Tactical-overview Widget" and version " >= 19.10.0 < 19.10.1" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Service-monitoring Widget Search vendor "Centreon" for product "Centreon Service-monitoring Widget" | < 1.6.4 Search vendor "Centreon" for product "Centreon Service-monitoring Widget" and version " < 1.6.4" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Service-monitoring Widget Search vendor "Centreon" for product "Centreon Service-monitoring Widget" | >= 18.10.0 < 18.10.5 Search vendor "Centreon" for product "Centreon Service-monitoring Widget" and version " >= 18.10.0 < 18.10.5" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Service-monitoring Widget Search vendor "Centreon" for product "Centreon Service-monitoring Widget" | >= 19.04.0 < 19.04.3 Search vendor "Centreon" for product "Centreon Service-monitoring Widget" and version " >= 19.04.0 < 19.04.3" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Service-monitoring Widget Search vendor "Centreon" for product "Centreon Service-monitoring Widget" | >= 19.10.0 < 19.10.2 Search vendor "Centreon" for product "Centreon Service-monitoring Widget" and version " >= 19.10.0 < 19.10.2" | - |
Affected
|