Impact
Centreon's centre-open-tickets module stores the message_confirm field without sanitization and then renders it through the Smarty template engine with no security policy enabled. An attacker who is authenticated with low privileges can inject arbitrary template code that the server executes, allowing read access to environment variables and secrets and potentially causing the platform to crash. This vulnerability permits complete compromise of confidentiality, integrity, and availability of the Centreon Infra Monitoring environment.
Affected Systems
The vulnerability affects the Centreon Infra Monitoring product in the centre-open-tickets module. No specific version numbers are listed, but the flaw exists in the current release at the time of the advisory. Users of Centreon who have any authenticated session, including low-privilege accounts, are at risk.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity. The EPSS score is below 1%, suggesting a very low probability of exploitation observed so far, and the issue is not yet listed in the CISA KEV catalog. Nonetheless, because the attack requires only a low-privilege authenticated session, the likely vector is internal, and exploitation is straightforward once a user logs on. The lack of a security policy in Smarty removes the barrier to executing arbitrary code, making the vulnerability highly effective for an attacker who has gained access to the platform.
OpenCVE Enrichment