CVE-2025-12513 MEDIUM

CVE-2025-12513: A user with elevated privileges can inject XSS in the Hosts configuration parameters page

Vendor Centreon
Product Infra Monitoring
Weakness CWE-79 · XSS
Published January 5, 2026
Last update January 8, 2026

CVSS base score

6.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts configuration form modules) allows Stored XSS to users with high privileges. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.

Key dates

02Disclosure timeline

January 5, 2026 CVE published
January 8, 2026 Record updated