On the monitoring event logs page, it is possible to alter the http request to insert a payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection. This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
History

Sat, 23 Aug 2025 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Centreon
Centreon centreon
Centreon centreon Web
Vendors & Products Centreon
Centreon centreon
Centreon centreon Web

Fri, 22 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Aug 2025 19:00:00 +0000

Type Values Removed Values Added
Description On the monitoring event logs page, it is possible to alter the http request to insert a payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection. This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
Title Second order SQL injection available to user with low privilege
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Centreon

Published: 2025-08-22T18:56:28.027Z

Updated: 2025-08-22T20:12:00.289Z

Reserved: 2025-06-27T14:34:22.260Z

Link: CVE-2025-6791

cve-icon Vulnrichment

Updated: 2025-08-22T20:11:52.080Z

cve-icon NVD

Status : Received

Published: 2025-08-22T19:15:40.537

Modified: 2025-08-22T19:15:40.537

Link: CVE-2025-6791

cve-icon Redhat

No data.