Centreon Centreon-Web OS Command Injection Vulnerability in Backup Configuration Modules

Vulnerability

A vulnerability allowing OS command injection has been identified in Centreon Centreon-Web, specifically within the backup configuration modules. This issue is present in Centreon-Web versions Cloud 25.03, 24.10.0 prior to 24.10.9, 24.04.0 prior to 24.04.15, and 23.10.0 prior to 23.10.24.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the server where Centreon-Web is running.

Added: Jun 10, 2025, 8:17 AM
Updated: Jun 10, 2025, 8:17 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.