CVE-2025-3767: SQL Injection in Centreon BAM boolean KPI listing
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection.
This page is only accessible to authenticated users with high privileges.
This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3767?
CVE-2025-3767 has been classified as a high-severity vulnerability due to its potential for SQL Injection attacks.
How do I fix CVE-2025-3767?
To mitigate CVE-2025-3767, it is recommended to upgrade Centreon BAM to the latest fixed version available.
What systems are affected by CVE-2025-3767?
CVE-2025-3767 affects Centreon BAM versions ranging from 23.04 up to 24.10.1.
What type of vulnerability is CVE-2025-3767?
CVE-2025-3767 is an SQL Injection vulnerability resulting from improper neutralization of special elements.
Who can exploit CVE-2025-3767?
CVE-2025-3767 can be exploited by authenticated users with high privileges.