Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22425
Reference (s):
- https://code610.blogspot.com/2020/04/postauth-sqli-in-centreon-1910-1el7.html,
- https://github.com/c610/free/