MEDIUM
A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration page
Published Oct 14, 2025
6.8
MEDIUMCVSS 3.1
EPSS 0.26%
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps manufacturer configuration modules) allows Stored XSS by users with elevated privileges.
This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.
Affected products
-
- Version 23.10.0StatusaffectedConstraints<23.10.28
- Version 24.04.0StatusaffectedConstraints<24.04.18
- Version 24.10.0StatusaffectedConstraints<24.10.13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Centreon | Infra Monitoring | unaffected |
|
OR
- ≥ 23.10.0 · < 23.10.28
- ≥ 24.04.0 · < 24.04.18
- ≥ 24.10.0 · < 24.10.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/centreon/centreon/releases release-notesRelease Notes
- https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-54889-centreon-web-all-versions-medium-severity-5123 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/centreon/centreon/releases | release-notesRelease Notes | |
| https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-54889-centreon-web-all-versions-medium-severity-5123 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Centreon
Published Oct 14, 2025
Updated Oct 15, 2025
Reserved Jul 31, 2025
Link CVE-2025-54889
CISA Vulnrichment
Updated Oct 14, 2025