allows Stored
XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 26 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon open Tickets
|
|
| CPEs | cpe:2.3:a:centreon:open_tickets:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Centreon open Tickets
|
Mon, 05 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon |
|
| Vendors & Products |
Centreon
Centreon centreon |
Mon, 22 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4. | |
| Title | A user with elevated privileges can inject XSS in the Notification rules configuration page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2026-01-05T09:51:56.936Z
Reserved: 2025-08-01T13:57:56.199Z
Link: CVE-2025-8460
Updated: 2025-12-22T13:06:44.990Z
Status : Analyzed
Published: 2025-12-22T11:15:58.730
Modified: 2026-01-26T15:51:35.110
Link: CVE-2025-8460
No data.
OpenCVE Enrichment
Updated: 2025-12-23T22:40:21Z