PT-2024-22600 · Checkmk · Checkmk

Published

2024-06-25

·

Updated

2024-12-04

·

CVE-2024-28832

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.3.0p7 Checkmk versions prior to 2.2.0p28 Checkmk versions prior to 2.1.0p45 Checkmk version 2.0.0
Description The issue allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings. This is a Stored XSS issue in the Crash Report page.
Recommendations For versions prior to 2.3.0p7, update to version 2.3.0p7 or later. For versions prior to 2.2.0p28, update to version 2.2.0p28 or later. For versions prior to 2.1.0p45, update to version 2.1.0p45 or later. For version 2.0.0, consider upgrading to a newer version as this version is end-of-life.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28832

Affected Products

Checkmk