First published: Thu Apr 24 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection. A user with high privileges is able to become administrator by intercepting the contact form request and altering its payload. This issue affects Centreon: from 22.10.0 before 22.10.28, from 23.04.0 before 23.04.25, from 23.10.0 before 23.10.20, from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.
Credit: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon | >=22.10.0<22.10.28>=23.04.0<23.04.25>=23.10.0<23.10.20>=24.04.0<24.04.10>=24.10.0<24.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3872 is classified as a high severity vulnerability due to the potential for SQL injection and privilege escalation.
To fix CVE-2025-3872, update Centreon centreon-web to a version that addresses this vulnerability, specifically versions beyond 22.10.28, 23.04.25, 23.10.20, and 24.10.4.
CVE-2025-3872 affects users with high privileges on the Centreon centreon-web application prior to the specified patched versions.
CVE-2025-3872 is caused by improper neutralization of special elements used in an SQL command, allowing SQL injection.
Exploitation of CVE-2025-3872 typically requires authenticated access with high privileges in the Centreon centreon-web application.