8.4

CVE-2025-4648

The content of a SVG file, received as input 

in Centreon web, was not properly checked. Allows Reflected XSS.
A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request.
This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CentreonCentreon Web Version >= 22.10.0 < 22.10.29
CentreonCentreon Web Version >= 23.04.0 < 23.04.27
CentreonCentreon Web Version >= 23.10.0 < 23.10.22
CentreonCentreon Web Version >= 24.04.0 < 24.04.11
CentreonCentreon Web Version >= 24.10.0 < 24.10.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.233
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 1.7 3.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
bd4443e6-1eef-43f3-9886-25fc9ceeaae7 8.4 1.7 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.