Cross-site Scripting Vulnerability in Centreon Infra Monitoring by Centreon
CVE-2025-8460
6.8MEDIUM
What is CVE-2025-8460?
A security flaw has been identified in Centreon Infra Monitoring, where improper handling of input during web page generation allows users with elevated privileges to insert malicious scripts. This results in stored cross-site scripting (XSS), potentially exposing sensitive information and compromising user sessions. The vulnerability affects several versions of the product, necessitating an immediate update to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Infra Monitoring 24.10.0 < 24.10.5
Infra Monitoring 24.04.0 < 24.04.5
Infra Monitoring 23.10.0 < 23.10.4
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcelo Queiroz
