← Vulnerability feed

Vulnerability record · CVE-2019-13024 · published 1 July 2019

CVE-2019-13024: Centreon command injection vulnerability

Centreon · Centreon

Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).

8.8 CVSS 3.0 High EPSS 32% · top 1.7% CWE-77 · Command injection
8.8CVSS 3.0 base score, v2 9.0
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-13024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-3827Centreon vulnerabilityA vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of …EPSS 0.83%9.8CVE-2021-37558Centreon sql injection vulnerabilityA SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to exec…EPSS 2.1%9.8CVE-2019-17647Centreon sql injection vulnerabilityAn issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/ho…EPSS 1.8%9.8CVE-2018-21024Centreon unrestricted file upload vulnerabilitylicenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.EPSS 2.2%9.8CVE-2019-16194Centreon sql injection vulnerabilitySQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOn…EPSS 1.6%9.8CVE-2018-19281Centreon sql injection vulnerabilityCentreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.EPSS 1.8%9.8CVE-2018-11587Centreon code injection vulnerabilityThere is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…EPSS 4.2%9.8CVE-2018-11589Centreon sql injection vulnerabilityMultiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the i…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2019-13024), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.