CVE-2025-12514: A user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules configuration parameters
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows
SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12514?
CVE-2025-12514 has a severity level that indicates it poses a significant risk due to potential SQL injection vulnerabilities.
How do I fix CVE-2025-12514?
To fix CVE-2025-12514, upgrade to the latest versions of Centreon Open-tickets that resolve the SQL injection vulnerability.
Who is affected by CVE-2025-12514?
CVE-2025-12514 affects users of Centreon Infra Monitoring - Open-tickets versions between 23.10.0 and 24.10.5.
What type of vulnerability is CVE-2025-12514?
CVE-2025-12514 is classified as an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands.
Can CVE-2025-12514 be exploited by low-privileged users?
No, CVE-2025-12514 requires elevated privileges for exploitation, making it a concern primarily for users with high access levels.