allows Stored XSS by users with elevated privileges.
This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon centreon Web
|
|
| CPEs | cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Centreon centreon Web
|
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon |
|
| Vendors & Products |
Centreon
Centreon centreon |
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28. | |
| Title | A user with elevated privileges can inject XSS in the SNMP traps group configuration page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2025-10-15T13:12:33.859Z
Reserved: 2025-07-31T18:22:28.420Z
Link: CVE-2025-54892
Updated: 2025-10-14T16:05:13.881Z
Status : Analyzed
Published: 2025-10-14T15:16:10.250
Modified: 2025-10-22T14:08:08.843
Link: CVE-2025-54892
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:42:53Z