PT-2025-52645 · Centreon · Centreon Infra Monitoring

Marcelo Queiroz

·

Published

2025-12-22

·

Updated

2025-12-22

·

CVE-2025-8460

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Centreon Infra Monitoring versions 23.10.0 through 23.10.4 Centreon Infra Monitoring versions 24.04.0 through 24.04.5 Centreon Infra Monitoring versions 24.10.0 through 24.10.5
Description The software contains an Improper Neutralization of Input During Web Page Generation issue, specifically a Stored Cross-site Scripting (XSS) condition. This allows users with elevated privileges to execute malicious scripts. The issue is located within the Notification rules and Open tickets module.
Recommendations Update Centreon Infra Monitoring versions 23.10.0 through 23.10.4 to version 23.10.5 or later. Update Centreon Infra Monitoring versions 24.04.0 through 24.04.5 to version 24.04.6 or later. Update Centreon Infra Monitoring versions 24.10.0 through 24.10.5 to version 24.10.6 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-8460

Affected Products

Centreon Infra Monitoring