We found results for “”
CVE-2025-4648
Good to know:
Date: May 13, 2025
Download of Code Without Integrity Check vulnerability in Centreon web allows Reflected XSS. A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.
Severity Score
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version https://github.com/centreon/centreon.git - centreon-web-24.04.11;https://github.com/centreon/centreon.git - centreon-web-24.10.5;https://github.com/centreon/centreon.git - centreon-web-23.10.22;https://github.com/centreon/centreon.git - centreon-web-23.04.27;https://github.com/centreon/centreon.git - centreon-web-22.10.29
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


