SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 26 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon open Tickets
|
|
| CPEs | cpe:2.3:a:centreon:open_tickets:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Centreon open Tickets
|
Mon, 05 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon |
|
| Vendors & Products |
Centreon
Centreon centreon |
Mon, 22 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4. | |
| Title | A user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules configuration parameters | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2026-01-05T09:52:48.786Z
Reserved: 2025-10-30T15:26:40.360Z
Link: CVE-2025-12514
Updated: 2025-12-22T13:03:11.809Z
Status : Analyzed
Published: 2025-12-22T11:15:56.990
Modified: 2026-01-26T15:52:38.793
Link: CVE-2025-12514
No data.
OpenCVE Enrichment
Updated: 2025-12-23T22:40:23Z