Download of Code Without Integrity Check Vulnerability in Centreon Web
CVE-2025-4648
8.4HIGH
What is CVE-2025-4648?
A vulnerability exists in Centreon Web that permits a user with elevated privileges to exploit reflected cross-site scripting (XSS) by manipulating the content of SVG media during submission requests. This security flaw enables unauthorized code execution, posing significant risks to the integrity of the system. Affected versions span from 22.10.0 up to 24.10.4, requiring immediate attention and updates to mitigate potential security breaches.
Affected Version(s)
web 24.10.0 < 24.10.5
web 24.04.0 < 24.04.11
web 23.10.0 < 23.10.22
