Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
24.10.0 (custom) before 24.10.5
24.04.0 (custom) before 24.04.5
23.10.0 (custom) before 23.10.4
Credits
Marcelo Queiroz
References
github.com/centreon/centreon/releases
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.