CVE-2020-13252
PHP vulnerability analysis and mitigation

Overview

Centreon before version 19.04.15 contains a remote code execution vulnerability (CVE-2020-13252) that allows authenticated attackers to execute arbitrary OS commands. The vulnerability exists in the RRDdatabase_status_path parameter that can be exploited via a main.get.php request followed by accessing the include/views/graphs/graphStatus/displayServiceStatus.php page (CVE Details, Centreon GitHub).

Technical details

The vulnerability stems from improper input validation in the RRDdatabase_status_path parameter. An attacker can inject shell metacharacters into this parameter through the application's web interface. The exploitation involves sending a specially crafted request to main.get.php with the manipulated RRDdatabase_status_path value, followed by triggering the execution through the displayServiceStatus.php page which uses the popen() function to execute commands (Security Blog).

Impact

When successfully exploited, this vulnerability allows authenticated attackers to execute arbitrary operating system commands on the underlying server with the privileges of the web application. This could lead to complete system compromise, including the ability to read sensitive files, modify system configurations, and potentially gain persistent access to the server (CVE Details).

Exploitability

The vulnerability requires valid authentication credentials to exploit. A proof-of-concept exploit has been publicly documented that demonstrates how an authenticated user can inject shell commands through the RRDdatabase_status_path parameter and achieve remote code execution. The exploit involves manipulating specific application parameters and triggering the execution through a sequence of HTTP requests (Security Blog).

Mitigation and workarounds

The vulnerability has been patched in Centreon version 19.04.15. Organizations using affected versions should upgrade to version 19.04.15 or later to mitigate this vulnerability. The fix was implemented through proper input validation and sanitization of the RRDdatabase_status_path parameter (Centreon GitHub).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-52777CRITICAL9.4
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52775HIGH8.8
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52774MEDIUM6.1
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52773MEDIUM6.1
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52772MEDIUM5.5
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management