Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Centreon Web 授权问题漏洞
Vulnerability Description
Centreon Web是法国Centreon公司的一套开源的系统监控工具 。该产品主要提供对网络、系统和应用程序等资源的监控功能。 Centreon Web 19.04.3及之前版本中存在授权问题漏洞,该漏洞源于用户在修改密码时,本应该为NULL的contact_autologin_key字段变成了空。攻击者可利用该漏洞绕过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A