Cross-site Scripting Vulnerability in Centreon Infra Monitoring by Centreon
CVE-2025-8460
6.8MEDIUM
What is CVE-2025-8460?
A security flaw has been identified in Centreon Infra Monitoring, where improper handling of input during web page generation allows users with elevated privileges to insert malicious scripts. This results in stored cross-site scripting (XSS), potentially exposing sensitive information and compromising user sessions. The vulnerability affects several versions of the product, necessitating an immediate update to mitigate risks.
Affected Version(s)
Infra Monitoring 24.10.0 < 24.10.5
Infra Monitoring 24.04.0 < 24.04.5
Infra Monitoring 23.10.0 < 23.10.4
