Centreon centreon-open-tickets
cpe:2.3:a:centreon:centreon:*:*:*:*:*:*:*
A critical Server-Side Template Injection (SSTI) vulnerability has been identified in the Centreon open tickets module. This vulnerability allows for Remote Code Execution (RCE) because the message_confirm field is stored without proper sanitization. The unsanitized input is rendered through Smarty without any security policy, enabling authenticated users to inject and execute arbitrary code on the server. The exploitation of this vulnerability could lead to the disclosure of environment secrets and impact the availability of the Centreon Infra Monitoring product.
Exploitation of this vulnerability allows authenticated users to execute arbitrary code on the server, potentially leading to unauthorized access, modification of data, and disruption of services. Additionally, it could result in the disclosure of sensitive environment secrets.
Users can upgrade to Centreon Open Tickets versions 26.05.1, 25.10.9, 24.10.14, or Centreon Web versions 25.10.15 and 24.10.28 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.