Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4647


Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS. A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.


Published

2025-05-13T10:15:29.317

Last Modified

2025-10-22T14:13:18.460

Status

Analyzed

Source

bd4443e6-1eef-43f3-9886-25fc9ceeaae7

Severity

CVSSv3.1: 8.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application centreon centreon_web < 22.10.29 Yes
Application centreon centreon_web < 23.04.27 Yes
Application centreon centreon_web < 23.10.22 Yes
Application centreon centreon_web < 24.04.11 Yes
Application centreon centreon_web < 24.10.5 Yes

References