CVE-2025-12519
Last modified
CVE-2025-12519 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Centreon | Centreon Web | >= 24.04.0, < 24.04.19 |
| Centreon | Centreon Web | >= 24.10.0, < 24.10.15 |
| Centreon | Centreon Web | >= 25.10.0, < 25.10.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-12519?
How severe is CVE-2025-12519?
How do I fix CVE-2025-12519?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12513Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-12514Improper Neutralization of Special Elements used in an SQL C…7.2
- CVE-2025-12515Systemic Internal Server Errors - HTTP 500 ResponseThis issu…9.8
- CVE-2025-12516Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue a…9.8
- CVE-2025-12517Credits Page not Matching Versions in Use in the FirmwareThi…5.3
- CVE-2025-12518beefree.io SDK is vulnerable to Stored XSS in Social Media i…5.3
- CVE-2025-1252Heap-based Buffer Overflow vulnerability in RTI Connext Prof…7.1
- CVE-2025-12520The WP Airbnb Review Slider plugin for WordPress is vulnerab…4
- CVE-2025-12521The Analytify Pro plugin for WordPress is vulnerable to Sens…5.3
- CVE-2025-12524The Post Type Switcher plugin for WordPress is vulnerable to…5.4
- CVE-2025-12525The Locker Content plugin for WordPress is vulnerable to Sen…5.3
- CVE-2025-12526The Private Google Calendars plugin for WordPress is vulnera…4.3
Are you affected by CVE-2025-12519?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
