« Volver al listado

CVE-2025-54892

Estado: AnalizadaMedia (4.8)—

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules)

allows Stored XSS by users with elevated privileges.

This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-54892",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-54892",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-14T16:05:09.568499Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
      "affectedData": [
        {
          "vendor": "Centreon",
          "modules": [
            "SNMP traps group configuration"
          ],
          "product": "Infra Monitoring",
          "versions": [
            {
              "status": "affected",
              "version": "24.10.0",
              "lessThan": "24.10.13",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.04.0",
              "lessThan": "24.04.18",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "23.10.0",
              "lessThan": "23.10.28",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-10-14T15:16:10.250",
  "references": [
    {
      "url": "https://github.com/centreon/centreon/releases",
      "tags": [
        "Release Notes"
      ],
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7"
    },
    {
      "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-54892-centreon-web-all-versions-medium-severity-5121",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) \n\nallows Stored XSS by users with elevated privileges.\n\nThis issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28."
    }
  ],
  "lastModified": "2026-06-17T09:40:52.797",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52CE7EB8-492F-4469-9E01-8C63144D785F",
              "versionEndExcluding": "23.10.28",
              "versionStartIncluding": "23.10.0"
            },
            {
              "criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C3C1C61-F2EB-4900-9BB7-C80A6C538E5E",
              "versionEndExcluding": "24.04.18",
              "versionStartIncluding": "24.04.0"
            },
            {
              "criteria": "cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09800EB4-10FC-4667-9FC8-88D9A8BB2751",
              "versionEndExcluding": "24.10.13",
              "versionStartIncluding": "24.10.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7"
}