CVE-2019-13024
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the...
- Published
- Jul 1, 2019
- Updated
- Aug 4, 2024
- Assigning CNA
- mitre
- Evidence observed
- Jul 2, 2019
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:CModerate · next 30 days
- Percentile
- 97.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).
Sources
4- Centreon-RCEExploit
Centreon v.19.04 Remote Code Execution exploit (CVE-2019-13024)
- CVE-2019-13024Exploit
The official exploit code for Centreon v19.04 Remote Code Execution CVE-2019-13024
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.