CVE-2025-6791

HIGH

Centreon Web 23.10.0-23.10.25 - SQL Injection in Monitoring Event Logs Page

Title source: llm
STIX 2.1

Description

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
centreon/centreon_web 23.10.0 - 23.10.26
Published Aug 22, 2025
Tracked Since Feb 18, 2026