CVE detail
CVE-2019-15300 — CVE-2019-15300
Published 2019-11-27 · Modified 2026-06-17 · Vendor centreon · Product centreon_web · Source nvd
HIGH
severity
CVSS-derived band
0.0201
EPSS probability
exploitation probability, 30d
79.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References