CVE-2025-4648
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
13/05/2025
Last modified:
22/10/2025
Description
The content of a SVG file, received as input <br />
<br />
in Centreon web, was not properly checked. Allows Reflected XSS.<br />
A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request.<br />
This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | 22.10.0 (including) | 22.10.29 (excluding) |
| cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | 23.04.0 (including) | 23.04.27 (excluding) |
| cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | 23.10.0 (including) | 23.10.22 (excluding) |
| cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | 24.04.0 (including) | 24.04.11 (excluding) |
| cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | 24.10.0 (including) | 24.10.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



