Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25617 | User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26. |
Wed, 22 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* |
Sat, 23 Aug 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon Centreon centreon Web |
|
| Vendors & Products |
Centreon
Centreon centreon Centreon centreon Web |
Fri, 22 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26. | |
| Title | User with high privileges is able to introduce a SQLi using the Meta Service indicator page | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2025-08-22T19:01:11.903Z
Reserved: 2025-05-13T11:40:55.019Z
Link: CVE-2025-4650
Updated: 2025-08-22T19:01:05.703Z
Status : Analyzed
Published: 2025-08-22T19:15:38.980
Modified: 2025-10-22T14:05:53.193
Link: CVE-2025-4650
No data.
OpenCVE Enrichment
Updated: 2025-08-23T11:53:13Z
EUVD