HIGH
Second order SQL injection available to user with low privilege
Published Aug 22, 2025
8.8
HIGHCVSS 3.1
EPSS 0.34%
Description
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.
Affected products
-
- Version 23.10.0StatusaffectedConstraints<23.10.26
- Version 24.04.0StatusaffectedConstraints<24.04.16
- Version 24.10.0StatusaffectedConstraints<24.10.9
- Version
OR
- ≥ 23.10.0 · < 23.10.26
- ≥ 24.04.0 · < 24.04.16
- ≥ 24.10.0 · < 24.10.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25618 Advisory
- https://github.com/centreon/centreon/releases release-notesRelease Notes
- https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-6791-centreon-web-all-versions-high-severity-4900 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25618 | Advisory | |
| https://github.com/centreon/centreon/releases | release-notesRelease Notes | |
| https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-6791-centreon-web-all-versions-high-severity-4900 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Centreon
Published Aug 22, 2025
Updated Sep 16, 2025
Reserved Jun 27, 2025
Link CVE-2025-6791
CISA Vulnrichment
Updated Aug 22, 2025
ENISA EUVD
EUVD-2025-25618 Assigner Centreon
Published Aug 22, 2025
Updated Sep 16, 2025
Exploited since n/a
Link EUVD-2025-25618