CVE-2025-6791: Second order SQL injection available to user with low privilege
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6791?
CVE-2025-6791 has been rated with high severity due to its potential for SQL injection and data manipulation.
How do I fix CVE-2025-6791?
To fix CVE-2025-6791, update Centreon web to the latest versions beyond 24.10.9, 24.04.16, or 23.10.26.
What type of vulnerability is CVE-2025-6791?
CVE-2025-6791 is an SQL injection vulnerability caused by improper neutralization of special elements in SQL commands.
Which versions of Centreon web are affected by CVE-2025-6791?
Centreon web versions from 23.10.0 up to 23.10.26, 24.04.0 up to 24.04.16, and 24.10.0 up to 24.10.9 are affected by CVE-2025-6791.
What impact can CVE-2025-6791 have on my system?
CVE-2025-6791 can allow an attacker to manipulate the database through crafted SQL queries, potentially leading to unauthorized data access or modification.