← Vulnerability feed

Vulnerability record · CVE-2018-21024 · published 8 October 2019

CVE-2018-21024: Centreon unrestricted file upload vulnerability

Centreon · Centreon

licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

9.8 CVSS 3.1 Critical EPSS 2.2% · top 17.9% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2019/10/09/2 Mailing ListPatchThird Party Advisory
https://github.com/centreon/centreon/pull/7085 Third Party Advisory
https://www.openwall.com/lists/oss-security/2019/10/08/1 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/10/09/2 Mailing ListPatchThird Party Advisory
https://github.com/centreon/centreon/pull/7085 Third Party Advisory
https://www.openwall.com/lists/oss-security/2019/10/08/1 Mailing ListPatchThird Party Advisory

Track CVE-2018-21024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-3827Centreon vulnerabilityA vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of …EPSS 0.83%9.8CVE-2021-37558Centreon sql injection vulnerabilityA SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to exec…EPSS 2.1%9.8CVE-2019-17647Centreon sql injection vulnerabilityAn issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/ho…EPSS 1.8%9.8CVE-2019-16194Centreon sql injection vulnerabilitySQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOn…EPSS 1.6%9.8CVE-2018-19281Centreon sql injection vulnerabilityCentreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.EPSS 1.8%9.8CVE-2018-11587Centreon code injection vulnerabilityThere is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…EPSS 4.2%9.8CVE-2018-11589Centreon sql injection vulnerabilityMultiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the i…EPSS 2.1%8.8CVE-2022-42424Centreon poller broker config SQL injection privilege escalationCentreon fails to validate a user-supplied string before building SQL queries when handling requests to modify poller broker configuration. An authen…EPSS 76%analysed

Source: NIST National Vulnerability Database (record CVE-2018-21024), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.