CVE-2025-15029
🟠 Łataj w tym tygodniu
Wstrzyknięcie SQL w Centreon Infra Monitoring umożliwia nieautoryzowany dostęp do bazy danych.
CVSS
9.8
EPSS
13.0%
Exploit
none
Vendor
centreon
Opis źródłowy (NVD)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 13.0% |
| Opublikowano (NVD) | 2026-01-05 15:15:44 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://github.com/centreon/centreon/releases (bd4443e6-1eef-43f3-9886-25fc9ceeaae7) [Release Notes]
- https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-15029-centreon-awie-critical-severity-5356 (bd4443e6-1eef-43f3-9886-25fc9ceeaae7) [Patch, Vendor Advisory]