Stored XSS Vulnerability in Checkmk Pop-Ups
CVE-2024-28831
5.4MEDIUM
What is CVE-2024-28831?
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p7
Checkmk 2.2.0 < 2.2.0p28