Centreon centreon-web
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*
- >= 24.10.0, < 24.10.9
- >= 24.04.0, < 24.04.15
- >= 23.10.0, < 23.10.24
- 25.03
A vulnerability allowing OS command injection has been identified in Centreon Centreon-Web, specifically within the backup configuration modules. This issue is present in Centreon-Web versions Cloud 25.03, 24.10.0 prior to 24.10.9, 24.04.0 prior to 24.04.15, and 23.10.0 prior to 23.10.24.
Exploitation of this vulnerability allows for arbitrary OS command execution on the server where Centreon-Web is running.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.