{"id":"CVE-2024-45754","details":"An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access.","modified":"2026-08-12T03:51:12.223646332Z","published":"2024-10-11T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45754.json"},"references":[{"type":"WEB","url":"https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-45754-centreon-mbi-high-severity-3888"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45754.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45754"},{"type":"PACKAGE","url":"https://github.com/centreon/centreon/releases"},{"type":"ARTICLE","url":"https://www.algosecure.fr/actualites/blog"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/centreon/centreon","events":[{"introduced":"e01b9bdfda598becd746e734fd5ab6888440439c"},{"fixed":"637c5e4f55d450821b1be433bda829f72f7e813f"},{"introduced":"6af71198938611074c5754b3d4772b60cc627d0e"},{"fixed":"44bd4012d45a93e32c82c5f7363c4035a4f8ee0c"},{"introduced":"78bb6bc7a94c393a26e016b00b8648558350df07"},{"fixed":"f9bc5c80e258b20b2c513f05293bc30261c754eb"},{"introduced":"424c7902ba197d695862042500e5ee98e241baa6"},{"fixed":"eb9b31ff47eaca1a753795345cc879220e789e0b"}],"database_specific":{"extracted_events":[{"introduced":"24.04.x"},{"fixed":"24.04.3"},{"introduced":"23.10.x"},{"fixed":"23.10.8"},{"introduced":"23.04.x"},{"fixed":"23.04.11"},{"introduced":"22.10.x"},{"fixed":"22.10.11"}],"source":"DESCRIPTION"}}],"versions":["centreon-web-22.10.10","centreon-web-22.10.9","centreon-web-22.10.8","centreon-open-tickets-22.10.1","centreon-gorgone-22.10.1","centreon-dsm-22.10.1","centreon-web-22.10.7","centreon-widget-service-monitoring-22.10.2","centreon-web-22.10.6","centreon-web-22.10.5","centreon-web-22.10.4","centreon-web-22.10.3","centreon-widget-tactical-overview-22.10.0","centreon-widget-single-metric-22.10.0","centreon-widget-servicegroup-monitoring-22.10.0","centreon-widget-service-monitoring-22.10.0","centreon-widget-ntopng-listing-22.10.0","centreon-widget-live-top10-memory-usage-22.10.0","centreon-widget-live-top10-cpu-usage-22.10.0","centreon-widget-httploader-22.10.0","centreon-widget-hostgroup-monitoring-22.10.0","centreon-widget-host-monitoring-22.10.0","centreon-widget-grid-map-22.10.0","centreon-widget-graph-monitoring-22.10.0","centreon-widget-global-health-22.10.0","centreon-widget-engine-status-22.10.0","centreon-web-22.10.2","centreon-open-tickets-22.10.0","centreon-ha-22.10.0","centreon-gorgone-22.10.0","centreon-dsm-22.10.0","centreon-awie-22.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45754.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}