CVE-2015-1560
HIGH 7.5EPSS 6.7%
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 6.69% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2015-07-14
- Updated
- 2024-08-06
Proof-of-concept exploits (1)
- Iansus/Centreon-CVE-2015-1560_15613★ · 2015-07-31