CVE-2025-15029: An unauthenticated user is able to introduce SQL Injection using the Awie export module
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15029?
CVE-2025-15029 is considered a high-severity SQL Injection vulnerability affecting Centreon Infra Monitoring.
How do I fix CVE-2025-15029?
To resolve CVE-2025-15029, it is recommended to upgrade Centreon Infra Monitoring to version 25.10.2 or later, or 24.10.3 or later.
Who is affected by CVE-2025-15029?
CVE-2025-15029 affects users of Centreon Infra Monitoring versions between 25.10.0 and 25.10.2, 24.10.0 and 24.10.3, and 24.04.0 and 24.04.3.
What type of vulnerability is CVE-2025-15029?
CVE-2025-15029 is classified as an SQL Injection vulnerability due to improper neutralization of special elements used in SQL commands.
Can an unauthenticated user exploit CVE-2025-15029?
Yes, CVE-2025-15029 can be exploited by an unauthenticated user, allowing unauthorized access to sensitive data.