CVE-2025-3872: Centreon Web

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection. A user with high privileges is able to become administrator by intercepting the contact form request and altering its payload. This issue affects Centreon: from 22.10.0 before 22.10.28, from 23.04.0 before 23.04.25, from 23.10.0 before 23.10.20, from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

Affected products

  • Centreon Centreon Web: from 22.10.0, before 22.10.28 (fixed in 22.10.28); from 23.04.0, before 23.04.25 (fixed in 23.04.25); from 23.10.0, before 23.10.20 (fixed in 23.10.20); from 24.04.0, before 24.04.10 (fixed in 24.04.10); from 24.10.0, before 24.10.4 (fixed in 24.10.4)

Published 2025-04-24. Last modified 2026-06-17.