to user with elevated privileges.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.1, from 24.10.0 before 24.10.4, from 24.04.0 before 24.04.8.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 26 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon dynamic Service Management
|
|
| CPEs | cpe:2.3:a:centreon:dynamic_service_management:*:*:*:*:*:*:*:* cpe:2.3:a:centreon:dynamic_service_management:25.10.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Centreon dynamic Service Management
|
Thu, 08 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon |
|
| Vendors & Products |
Centreon
Centreon centreon |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configuration modules) allows Stored XSS to user with elevated privileges. This issue affects Infra Monitoring: from 25.10.0 before 25.10.1, from 24.10.0 before 24.10.4, from 24.04.0 before 24.04.8. | |
| Title | A user with elevated privileges can inject XSS in the DSM Administration’s Extensions configuration page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2026-01-08T15:40:12.515Z
Reserved: 2025-10-30T14:13:08.892Z
Link: CVE-2025-12511
Updated: 2026-01-05T21:19:27.024Z
Status : Analyzed
Published: 2026-01-05T14:15:53.133
Modified: 2026-01-26T15:33:51.160
Link: CVE-2025-12511
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:17:09Z