CVE-2025-15029

Source
https://cve.org/CVERecord?id=CVE-2025-15029
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15029.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15029
Published
2026-01-05T14:34:02.986Z
Modified
2026-01-28T05:33:22.051176Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
An unauthenticated user is able to introduce SQL Injection using the Awie export module
Details

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user.

This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "cna_assigner": "Centreon",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15029.json"
}
References

Affected packages

Git / github.com/centreon/centreon

Affected ranges

Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "25.10.0"
        },
        {
            "fixed": "25.10.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "24.10.0"
        },
        {
            "fixed": "24.10.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "24.04.0"
        },
        {
            "fixed": "24.04.3"
        }
    ]
}

Affected versions

centreon-awie-24.*
centreon-awie-24.04.0
centreon-awie-24.10.0
centreon-dsm-24.*
centreon-dsm-24.04.0
centreon-dsm-24.04.2
centreon-dsm-24.10.0
centreon-gorgone-24.*
centreon-gorgone-24.04.0
centreon-ha-24.*
centreon-ha-24.04.0
centreon-open-tickets-24.*
centreon-open-tickets-24.04.0
centreon-open-tickets-24.10.0
centreon-open-tickets-24.10.1
centreon-web-24.*
centreon-web-24.04.0
centreon-web-24.04.2
centreon-web-24.10.0
centreon-web-24.10.1
centreon-web-24.10.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15029.json"