SQL Injection Vulnerability in Centreon Monitoring Event Logs
CVE-2025-6791

8.8HIGH

Key Information:

Vendor

Centreon

Status
Vendor
CVE Published:
22 August 2025

What is CVE-2025-6791?

A vulnerability exists within Centreon's Monitoring Event Logs module that allows an attacker to inject malicious SQL commands through manipulated HTTP requests. This flaw results in improper handling of special elements used in SQL commands, leading to unauthorized database access and potential data compromise. Affected versions include Centreon Web 24.10.0 to 24.10.8, 24.04.0 to 24.04.15, and 23.10.0 to 23.10.25.

Affected Version(s)

web 24.10.0 < 24.10.9

web 24.04.0 < 24.04.16

web 23.10.0 < 23.10.26

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SpawnZii for YesWeHack
.
CVE-2025-6791 : SQL Injection Vulnerability in Centreon Monitoring Event Logs