PT-2022-8911 · Checkmk · Checkmk

Published

2022-01-15

·

Updated

2024-07-23

·

CVE-2020-28919

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 1.6.0x prior to 1.6.0p19
Description A stored cross site scripting (XSS) issue allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
Recommendations For Checkmk versions 1.6.0x prior to 1.6.0p19, update to version 1.6.0p19 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-28919

Affected Products

Checkmk