Cross-site Scripting Vulnerability in Centreon Web Affects Multiple Versions
CVE-2025-4647
8.4HIGH
What is CVE-2025-4647?
A Cross-site Scripting (XSS) vulnerability in Centreon Web allows an attacker with elevated privileges to manipulate the content of existing SVG files. This manipulation can lead to reflected XSS, compromising the integrity of web page rendering and potentially allowing unauthorized actions or data exposure. Affected versions span from 22.10.0 to 24.10.5 among others, necessitating immediate updates to mitigate risks and enhance web security against exploit attempts.
Affected Version(s)
web 24.10.0 < 24.10.5
web 24.04.0 < 24.04.11
web 23.10.0 < 23.10.22
