PT-2017-19184 · Mathias Kettner+1 · Checkmk+1

Publicado

2017-06-21

·

Atualizado

2022-07-20

·

CVE-2017-9781

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Check MK versions 1.4.0x prior to 1.4.0p6
Description A cross site scripting (XSS) issue exists, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the username parameter when attempting authentication to "webapi.py", which is returned unencoded with content type text/html.
Recommendations For Check MK versions 1.4.0x prior to 1.4.0p6, update to version 1.4.0p6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "webapi.py" endpoint or avoiding the use of the username parameter until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9781
USN-5527-1
USN-5527-2

Produtos afetados

Checkmk
Ubuntu