← All CVEs

CVE-2025-15029

critical · 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

9.8
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2026-01-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
centreonawie>= 24.04.0, < 24.04.3
centreonawie>= 24.10.0, < 24.10.3
centreonawie>= 25.10.0, < 25.10.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-15029