CVE-2025-54890: A user with elevated privileges can inject XSS in the Hostgroups configuration page
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration page) allows Stored
XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19, from 23.10.0 before 23.10.29.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54890?
The severity of CVE-2025-54890 is considered high due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-54890?
To fix CVE-2025-54890, upgrade Centreon Infra Monitoring to versions 24.10.1 or higher, or apply the necessary patches provided by the vendor.
Who is affected by CVE-2025-54890?
CVE-2025-54890 affects users with elevated privileges using Centreon Infra Monitoring versions 24.10.0 to 24.10.15, 24.04.0 to 24.04.19, and 23.10.0 to 23.10.29.
What type of vulnerability is CVE-2025-54890?
CVE-2025-54890 is an Improper Neutralization of Input During Web Page Generation, specifically a stored cross-site scripting (XSS) vulnerability.
Can CVE-2025-54890 lead to data theft?
Yes, CVE-2025-54890 can lead to data theft as attackers can execute malicious scripts in the context of a user's session.