Stored XSS Vulnerability in Checkmk Crash Report Before Versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL)

CVE-2024-28832
4.8MEDIUM

Key Information

Vendor
Checkmk Gmbh
Status
Checkmk
Vendor
CVE Published:
25 June 2024

Summary

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

Affected Version(s)

Checkmk < 2.3.0p7

Checkmk < 2.2.0p28

Checkmk < 2.1.0p45

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

PS Positive Security GmbH
.