Skip to main content
security bulletin

CVE-2025-4648/CVE-2024-55575 - Centreon Web - High severity

  • March 12, 2025
  • 0 replies
  • 554 views

lpinsivy
Centreonian
Forum|alt.badge.img+21

Publication date: March 12, 2025

Component: centreon-web (on central server).

Feature: Media upload

 

Description: A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.

 

ReferenceCVE-2024-55575

CVSS8.4 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H 

SeverityHIGH

 

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Central server:

These versions include cumulative fixes from prior updates.

 

Reporter: SpawnZii working with YesWeHack

Submission: November 27, 2024
 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.

0 replies

Be the first to reply!