CVE-2022-42428 is a high-severity SQL injection vulnerability affecting Centreon, allowing authenticated remote attackers to escalate privileges to an administrator level. The flaw, identified as CWE-89, arises from improper validation of user-supplied strings during the modification of poller broker configurations. With a CVSS score of 8.8 (High), it has a low attack complexity and requires only low privileges, posing a significant risk to confidentiality, integrity, and availability. While no public exploit code is currently available on platforms like Metasploit or ExploitDB, this CVE is on the "Hot List: Active" and has an elevated EPSS score, indicating a higher probability of exploitation and notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.04.19CPE matchmatch criteria | cpe:2.3:a:centreon:centreon:*:*:*:*:*:*:*:* | ||
>= 21.10.0, < 21.10.11CPE matchmatch criteria | cpe:2.3:a:centreon:centreon:*:*:*:*:*:*:*:* | ||
>= 22.04.0, < 22.04.6CPE matchmatch criteria | cpe:2.3:a:centreon:centreon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.