CVE-2025-54889: A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration page
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps manufacturer configuration modules) allows Stored XSS by users with elevated privileges.
This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54889?
CVE-2025-54889 is considered a high severity vulnerability due to its potential for Stored XSS attacks by users with elevated privileges.
How do I fix CVE-2025-54889?
To fix CVE-2025-54889, you should update Centreon Infra Monitoring to the latest version that is not affected, as per the vendor's release notes.
What versions are affected by CVE-2025-54889?
CVE-2025-54889 affects Centreon Infra Monitoring versions ranging from 23.10.0 to 23.10.28, and 24.04.0 to 24.04.18, including 24.10.0 to 24.10.13.
Who is impacted by CVE-2025-54889?
Users with elevated privileges in Centreon Infra Monitoring are primarily impacted by CVE-2025-54889, as they can exploit the Stored XSS vulnerability.
What type of vulnerability is CVE-2025-54889?
CVE-2025-54889 is classified as an Improper Neutralization of Input During Web Page Generation, commonly known as Cross-site Scripting (XSS).