← Back

CVE-2021-26804

nvd nist
Published: May 4, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.

Affected (3)

1 product
Centreon Web
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Centreon
Version 19.10.18
Version 20.04.8
Version 20.10.2

Timeline

No history available yet.