CVE-2024-55573: Centreon Web

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.

Affected products

  • Centreon Centreon Web: from 23.04.0, before 23.04.24 (fixed in 23.04.24); from 23.10.0, before 23.10.19 (fixed in 23.10.19); from 24.04.0, before 24.04.9 (fixed in 24.04.9); from 24.10.0, before 24.10.3 (fixed in 24.10.3)

Published 2025-01-23. Last modified 2026-06-17.