Back

HIGH

Second order SQL injection available to user with low privilege

Published Aug 22, 2025

Description

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Centreon
Published Aug 22, 2025
Updated Sep 16, 2025
Reserved Jun 27, 2025
CISA Vulnrichment
Updated Aug 22, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Centreon
Published Aug 22, 2025
Updated Sep 16, 2025
Exploited since n/a
EUVD-2025-25618