PT-2025-41933 · Centreon · Centreon Infra Monitoring

Marcelo Queiroz

·

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-54892

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Centreon Infra Monitoring versions 24.10.0 through 24.10.12 Centreon Infra Monitoring versions 24.04.0 through 24.04.17 Centreon Infra Monitoring versions 23.10.0 through 23.10.27
Description The software contains an Improper Neutralization of Input During Web Page Generation issue, specifically a Stored Cross-site Scripting condition. This affects the SNMP traps group configuration modules and can be exploited by users with elevated privileges. The issue allows for the injection of malicious scripts into web pages.
Recommendations Update Centreon Infra Monitoring to version 24.10.13 or later. Update Centreon Infra Monitoring to version 24.04.18 or later. Update Centreon Infra Monitoring to version 23.10.28 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54892

Affected Products

Centreon Infra Monitoring