8.4

CVE-2025-4648

A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.

The content of a SVG file, received as input 

in Centreon web, was not properly checked. Allows Reflected XSS.
A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request.
This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CentreonCentreon Web Version >= 22.10.0 < 22.10.29
CentreonCentreon Web Version >= 23.04.0 < 23.04.27
CentreonCentreon Web Version >= 23.10.0 < 23.10.22
CentreonCentreon Web Version >= 24.04.0 < 24.04.11
CentreonCentreon Web Version >= 24.10.0 < 24.10.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 1.7 3.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
bd4443e6-1eef-43f3-9886-25fc9ceeaae7 8.4 1.7 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://github.com/centreon/centreon/releases
Release Notes
https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55575-centreon-web-high-severity-4434
Vendor Advisory