CVE-2025-12513: A user with elevated privileges can inject XSS in the Hosts configuration parameters page
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts configuration form modules) allows Stored XSS to users with high privileges.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12513?
CVE-2025-12513 is classified as a high severity vulnerability due to its potential for stored XSS attacks on users with high privileges.
How do I fix CVE-2025-12513?
To fix CVE-2025-12513, upgrade Centreon Infra Monitoring to version 25.10.2 or above.
What types of applications are affected by CVE-2025-12513?
CVE-2025-12513 affects the Centreon Infra Monitoring applications, specifically versions between 24.04.0 and 24.04.19, as well as versions from 25.10.0 to 25.10.2.
What impact does CVE-2025-12513 have on users?
CVE-2025-12513 can allow attackers to execute malicious scripts in the context of high privilege users, potentially compromising sensitive information.
Who is primarily at risk from CVE-2025-12513?
Users with high privileges in Centreon Infra Monitoring are primarily at risk from CVE-2025-12513 due to the nature of the stored XSS vulnerability.