Skip to main content

Publication date: September 24th, 2025

Components: centreon-web

Description: A user with elevated privileges can inject XSS in the SNMP Traps group configuration page.

Reference: CVE-2025-54892

CVSS: 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N)

Severity: Medium

 

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server:

These versions include cumulative fixes from prior updates.

Reporter: Marcelo Queiroz

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.

 

 

Be the first to reply!