PT-2025-52643 · Centreon · Centreon Infra Monitoring - Open-Tickets

Marcelo Queiroz

·

Published

2025-12-22

·

Updated

2025-12-27

·

CVE-2025-12514

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Centreon Infra Monitoring - Open-tickets versions 23.10.0 through 23.10.4 Centreon Infra Monitoring - Open-tickets versions 24.04.0 through 24.04.5 Centreon Infra Monitoring - Open-tickets versions 24.10.0 through 24.10.5
Description A flaw exists in Centreon Infra Monitoring - Open-tickets related to the improper neutralization of special elements within SQL commands, leading to a potential SQL Injection issue. This impacts the Notification rules configuration parameters and Open tickets modules. Successful exploitation could allow a user with elevated privileges to inject malicious SQL code.
Recommendations Update Centreon Infra Monitoring - Open-tickets to version 23.10.5 or later. Update Centreon Infra Monitoring - Open-tickets to version 24.04.5 or later. Update Centreon Infra Monitoring - Open-tickets to version 24.10.5 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-12514

Affected Products

Centreon Infra Monitoring - Open-Tickets