PT-2022-11334 · Unknown+1 · Checkmk Raw Edition+1
Edgar Augusto Loyola Torres
·
Published
2022-01-02
·
Updated
2024-07-23
·
CVE-2021-40906
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CheckMK Raw Edition software versions 1.5.0 through 1.6.0
Description
The issue allows for Reflected XSS, enabling an attacker to inject malicious HTML content, including JavaScript or other client-side scripts, into a user's browser. This could lead to the opening of a backdoor on the device or the theft of session cookies from previously authenticated users, potentially through a man-in-the-middle attack. The exploitation requires access to a web service resource without the need for authentication.
Recommendations
For CheckMK Raw Edition software versions 1.5.0 through 1.6.0, consider implementing input sanitization for the vulnerable web service parameter to prevent Reflected XSS attacks. As a temporary workaround, restrict access to the unauthenticated zone of the web service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk Raw Edition
Ubuntu