CVE-2025-3767

Source
https://cve.org/CVERecord?id=CVE-2025-3767
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3767.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-3767
Published
2025-04-22T15:16:24.312Z
Modified
2026-04-10T05:25:50.045661Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SQL Injection in Centreon BAM boolean KPI listing
Details

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection.

This page is only accessible to authenticated users with high privileges.

This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.

Database specific
{
    "cna_assigner": "Centreon",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3767.json",
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/centreon/centreon

Affected ranges

Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "24.10"
        },
        {
            "fixed": "24.10.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "24.04"
        },
        {
            "fixed": "24.04.5"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "23.10"
        },
        {
            "fixed": "23.10.10"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "23.04"
        },
        {
            "fixed": "23.04.10"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3767.json"