PT-2022-11334 · Unknown+1 · Checkmk Raw Edition+1

Edgar Augusto Loyola Torres

·

Published

2022-01-02

·

Updated

2024-07-23

·

CVE-2021-40906

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CheckMK Raw Edition software versions 1.5.0 through 1.6.0
Description The issue allows for Reflected XSS, enabling an attacker to inject malicious HTML content, including JavaScript or other client-side scripts, into a user's browser. This could lead to the opening of a backdoor on the device or the theft of session cookies from previously authenticated users, potentially through a man-in-the-middle attack. The exploitation requires access to a web service resource without the need for authentication.
Recommendations For CheckMK Raw Edition software versions 1.5.0 through 1.6.0, consider implementing input sanitization for the vulnerable web service parameter to prevent Reflected XSS attacks. As a temporary workaround, restrict access to the unauthenticated zone of the web service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-40906
USN-5527-1

Affected Products

Checkmk Raw Edition
Ubuntu