{"id":"GHSA-jmgg-wx67-7qfv","summary":"Command Injection in Centreon","details":"Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.","aliases":["CVE-2020-13252"],"modified":"2026-09-10T03:49:05.913145026Z","published":"2021-06-22T15:23:33Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-20T22:17:17Z","nvd_published_at":"2020-05-21T04:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13252"},{"type":"WEB","url":"https://github.com/centreon/centreon/pull/8467"},{"type":"WEB","url":"https://engindemirbilek.github.io/centreon-19.10-rce"},{"type":"WEB","url":"https://github.com/EnginDemirbilek/EnginDemirbilek.github.io/blob/master/centreon-19.10-rce.html"},{"type":"WEB","url":"https://github.com/centreon/centreon/compare/19.04.13...19.04.15"}],"affected":[{"package":{"name":"centreon/centreon","ecosystem":"Packagist","purl":"pkg:composer/centreon/centreon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.04.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-jmgg-wx67-7qfv/GHSA-jmgg-wx67-7qfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}