Skip to content

TheCyberGeek/Centreon-20.04

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2020-12688 - Authenticated RCE Centreon 20.04

minHelpCommand.php command name variable RCE (CVE-2020-12688)

Centreon Latest Release Documentation: https://docs.centreon.com/current/en/releases/centreon-core.html

Discovered by: TheCyberGeek

Date Discovered: 30/04/2020

Date Disclosed: 15/06/2020

Command execution through unused minHelpCommand.php (removed in version 19.04). The removed function was accessible to logged in users who could trigger remote code execution by editing the command name variable.

About

CVE-2020-12688 - Authenticated RCE Centreon 20.04

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages