PT-2025-52644 · Centreon · Centreon Infra Monitoring

Marcelo Queiroz

·

Published

2025-12-22

·

Updated

2026-01-26

·

CVE-2025-54890

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Centreon Infra Monitoring versions 23.10.0 through 23.10.29 Centreon Infra Monitoring versions 24.04.0 through 24.04.19 Centreon Infra Monitoring versions 24.10.0 through 24.10.15
Description The software contains an Improper Neutralization of Input During Web Page Generation issue, specifically a Stored Cross-site Scripting (XSS) condition. This impacts the Hostgroup configuration page and can be exploited by users with elevated privileges. Stored XSS occurs when malicious scripts are injected into a website and stored on the server, allowing them to be executed whenever a user visits the affected page.
Recommendations Update Centreon Infra Monitoring to version 23.10.29 or later. Update Centreon Infra Monitoring to version 24.04.19 or later. Update Centreon Infra Monitoring to version 24.10.15 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54890

Affected Products

Centreon Infra Monitoring