OS Command Injection Vulnerability in Centreon Infra Monitoring Software
CVE-2025-5965
7.2HIGH
What is CVE-2025-5965?
A significant security flaw exists in Centreon Infra Monitoring where a user with elevated privileges can manipulate backup parameters. This vulnerability, which arises from improper handling of input in backup setup, enables an attacker to inject malicious OS commands. Specifically, it affects certain versions of Infra Monitoring, allowing unauthorized actions that could compromise the system. Users should ensure they are running updated versions to mitigate this risk.
Affected Version(s)
Infra Monitoring 25.10.0 < 25.10.2
Infra Monitoring 24.10.0 < 24.10.15
Infra Monitoring 24.04.0 < 24.04.19
