Centreon Centreon Web
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*
- < 25.10.8
- < 24.10.20
- < 24.04.24
A blind SQL injection vulnerability has been identified in the Centreon Web application running on Central Server on Linux, specifically within the Service Dependencies module. This vulnerability arises from unsanitized array keys during the deletion of service dependencies, allowing for manipulation of SQL queries. The issue affects Centreon Web on Central Server versions prior to 25.10.8, as well as 24.10.20 and 24.04.24.
Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information without being able to see the results of their queries directly.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.