Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4648


The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.


Published

2025-05-13T10:15:29.503

Last Modified

2025-10-22T14:12:11.843

Status

Analyzed

Source

bd4443e6-1eef-43f3-9886-25fc9ceeaae7

Severity

CVSSv3.1: 8.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application centreon centreon_web < 22.10.29 Yes
Application centreon centreon_web < 23.04.27 Yes
Application centreon centreon_web < 23.10.22 Yes
Application centreon centreon_web < 24.04.11 Yes
Application centreon centreon_web < 24.10.5 Yes

References