{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T22:21:21.686","vulnerabilities":[{"cve":{"id":"CVE-2025-4647","sourceIdentifier":"bd4443e6-1eef-43f3-9886-25fc9ceeaae7","published":"2025-05-13T10:15:29.317","lastModified":"2026-06-17T09:33:40.620","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS.\n\nA user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG.\n\nThis issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29."},{"lang":"es","value":"La vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web (XSS o \"Cross-site Scripting\") en la web de Centreon permite XSS reflejado. Un usuario con privilegios elevados puede eludir las medidas de depuración reemplazando el contenido de un SVG existente. Este problema afecta a la web: desde la versión 24.10.0 hasta la 24.10.5, desde la versión 24.04.0 hasta la 24.04.11, desde la versión 23.10.0 hasta la 23.10.22, desde la versión 23.04.0 hasta la 23.04.27, desde la versión 22.10.0 hasta la 22.10.29."}],"affected":[{"source":"bd4443e6-1eef-43f3-9886-25fc9ceeaae7","affectedData":[{"vendor":"Centreon","product":"web","defaultStatus":"unaffected","versions":[{"version":"24.10.0","lessThan":"24.10.5","versionType":"semver","status":"affected"},{"version":"24.04.0","lessThan":"24.04.11","versionType":"semver","status":"affected"},{"version":"23.10.0","lessThan":"23.10.22","versionType":"semver","status":"affected"},{"version":"23.04.0","lessThan":"23.04.27","versionType":"semver","status":"affected"},{"version":"22.10.0","lessThan":"22.10.29","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"bd4443e6-1eef-43f3-9886-25fc9ceeaae7","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.7,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T13:08:16.035524Z","id":"CVE-2025-4647","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"bd4443e6-1eef-43f3-9886-25fc9ceeaae7","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*","versionStartIncluding":"22.10.0","versionEndExcluding":"22.10.29","matchCriteriaId":"E8987E24-3449-4436-BBE0-BF3ECD4A79AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*","versionStartIncluding":"23.04.0","versionEndExcluding":"23.04.27","matchCriteriaId":"1CA620D6-AB8C-494E-9008-F4372C234F3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*","versionStartIncluding":"23.10.0","versionEndExcluding":"23.10.22","matchCriteriaId":"22F4DBC4-34EA-4B74-B049-B48C8A368438"},{"vulnerable":true,"criteria":"cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*","versionStartIncluding":"24.04.0","versionEndExcluding":"24.04.11","matchCriteriaId":"5F7169A7-4C43-440B-A7A1-BE6191FB676E"},{"vulnerable":true,"criteria":"cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*","versionStartIncluding":"24.10.0","versionEndExcluding":"24.10.5","matchCriteriaId":"58D9F6C2-9EDA-43B1-B18D-E6E6EDB17DDB"}]}]}],"references":[{"url":"https://github.com/centreon/centreon/releases","source":"bd4443e6-1eef-43f3-9886-25fc9ceeaae7","tags":["Release Notes"]},{"url":"https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55574-centreon-web-high-severity-4435","source":"bd4443e6-1eef-43f3-9886-25fc9ceeaae7","tags":["Vendor Advisory"]}]}}]}