CVE-2025-10023: A user with elevated privileges can inject XSS in the Services Meta-services configuration page
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules)
allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10023?
CVE-2025-10023 is classified as a high severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2025-10023?
To fix CVE-2025-10023, upgrade Centreon Infra Monitoring to version 24.10.10 or later, or apply the appropriate patches.
Who is affected by CVE-2025-10023?
CVE-2025-10023 affects users of Centreon Infra Monitoring versions from 24.10.0 to 24.10.9, as well as versions from 24.04.0 to 24.04.16, and from 23.10.0 to 23.10.26.
What types of attacks are possible with CVE-2025-10023?
CVE-2025-10023 allows for stored cross-site scripting (XSS) attacks, where malicious scripts can be injected and executed by users with elevated privileges.
Can CVE-2025-10023 be exploited remotely?
Yes, CVE-2025-10023 can be exploited remotely by attackers who can send malicious input to the vulnerable application.