On the monitoring event logs page, it is possible to alter the http request to insert a payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.
This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
Metrics
Affected Vendors & Products
References
History
Sat, 23 Aug 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Centreon
Centreon centreon Centreon centreon Web |
|
Vendors & Products |
Centreon
Centreon centreon Centreon centreon Web |
Fri, 22 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 22 Aug 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | On the monitoring event logs page, it is possible to alter the http request to insert a payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection. This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26. | |
Title | Second order SQL injection available to user with low privilege | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Centreon
Published: 2025-08-22T18:56:28.027Z
Updated: 2025-08-22T20:12:00.289Z
Reserved: 2025-06-27T14:34:22.260Z
Link: CVE-2025-6791

Updated: 2025-08-22T20:11:52.080Z

Status : Received
Published: 2025-08-22T19:15:40.537
Modified: 2025-08-22T19:15:40.537
Link: CVE-2025-6791

No data.