CVE-2025-3767: Centreon Bam

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.

Affected products

  • Centreon Centreon Bam: from 24.10, before 24.10.1 (fixed in 24.10.1); from 24.04, before 24.04.5 (fixed in 24.04.5); from 23.10, before 23.10.10 (fixed in 23.10.10); from 23.04, before 23.04.10 (fixed in 23.04.10)

Published 2025-04-22. Last modified 2026-06-17.