CVE-2025-4650

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
22/08/2025
Last modified:
22/10/2025

Description

User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 23.10.0 (including) 23.10.26 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 24.04.0 (including) 24.04.16 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 24.10.0 (including) 24.10.9 (excluding)