Vulnerability record · CVE-2024-23118 · published 1 April 2024
CVE-2024-23118: Centreon updateContactHostCommands SQL injection leads to remote code execution
Centreon · Centreon Web
Centreon's updateContactHostCommands function builds SQL queries from user-supplied input without proper validation, allowing SQL injection. Because the injection can be chained into code execution, an authenticated attacker can run arbitrary code as the service account on affected Centreon installations.
Description
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactHostCommands function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22298.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a high EPSS score, though exploitation requires authenticated access with elevated privileges.
What it is
Centreon's updateContactHostCommands function builds SQL queries from user-supplied input without proper validation, allowing SQL injection. Because the injection can be chained into code execution, an authenticated attacker can run arbitrary code as the service account on affected Centreon installations.
Impact
An attacker gains arbitrary code execution in the context of the Centreon service account, giving full control over the application's data and the host privileges of that account.
Attack surface
Reachable over the network through the Centreon web interface; the CVSS vector (AV:N/PR:H) and the advisory state that authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit is referenced; EPSS is high at roughly 0.53 (98.9th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor patch referenced in the Zero Day Initiative advisory ZDI-24-114.
- Restrict access to the Centreon web interface to trusted management networks.
- Enforce least privilege and review accounts with the high privileges needed to reach updateContactHostCommands.
- Audit and monitor database accounts used by Centreon for unexpected query patterns or privilege use.
Detection
- Monitor Centreon web and application logs for anomalous requests to endpoints invoking updateContactHostCommands.
- Alert on SQL error strings or unusual query patterns in Centreon database logs.
- Watch for unexpected child processes or command execution spawned by the Centreon service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-114/ | PatchThird Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-24-114/ | PatchThird Party Advisory |
Track CVE-2024-23118 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.