Vulnerability record · CVE-2022-42427 · published 29 March 2023
CVE-2022-42427: Centreon contact groups page SQL injection allows privilege escalation
Centreon · Centreon
Centreon fails to validate a user-supplied string before building SQL queries on the contact groups configuration page, creating a SQL injection flaw (CWE-89). An authenticated attacker can abuse it to escalate privileges to administrator level on affected installations. The record does not list specific affected versions.
Description
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18541.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and a very high EPSS score, though exploitation requires an authenticated low-privileged account and no KEV listing exists.
What it is
Centreon fails to validate a user-supplied string before building SQL queries on the contact groups configuration page, creating a SQL injection flaw (CWE-89). An authenticated attacker can abuse it to escalate privileges to administrator level on affected installations. The record does not list specific affected versions.
Impact
An attacker with a low-privileged account gains full administrative control of the Centreon installation, including high confidentiality, integrity and availability impact per the CVSS vector.
Attack surface
Reachable over the network through the contact groups configuration page; the CVSS vector (AV:N/PR:L/UI:N) and description confirm a valid low-privileged account is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high at 0.76134 (99.5th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the vendor patch for Centreon addressing ZDI-CAN-18541 as soon as it is available.
- Restrict access to the Centreon web interface and contact groups configuration page to trusted networks and accounts.
- Enforce least privilege: audit and reduce accounts with configuration-page access.
- Monitor and alert on unexpected privilege changes to administrator level.
- Review database logs for anomalous queries originating from the Centreon application.
Detection
- Search Centreon and database logs for SQL syntax or injection patterns in requests to the contact groups configuration page.
- Alert on new or modified administrator accounts, especially those created by low-privileged users.
- Baseline normal contact group configuration activity and flag deviations.
- Correlate web access logs with database query logs for the Centreon application user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-22-1398/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1398/ | Third Party AdvisoryVDB Entry |
Track CVE-2022-42427 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42427), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.