User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
2025-08-22T19:15:38.980
2025-10-22T14:05:53.193
Analyzed
bd4443e6-1eef-43f3-9886-25fc9ceeaae7
CVSSv3.1: 7.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | centreon | centreon_web | < 23.10.26 | Yes |
| Application | centreon | centreon_web | < 24.04.16 | Yes |
| Application | centreon | centreon_web | < 24.10.9 | Yes |