PT-2024-37347 · Checkmk · Checkmk

Published

2024-07-03

·

Updated

2024-09-16

·

CVE-2024-6052

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Checkmk versions prior to 2.3.0p8 Checkmk versions prior to 2.2.0p29 Checkmk versions prior to 2.1.0p45 Checkmk version 2.0.0
Description: The issue allows users to execute arbitrary scripts by injecting HTML elements, which can lead to the execution of malicious code. This is a result of a stored XSS flaw in the software.
Recommendations: For versions prior to 2.3.0p8, update to version 2.3.0p8 or later. For versions prior to 2.2.0p29, update to version 2.2.0p29 or later. For versions prior to 2.1.0p45, update to version 2.1.0p45 or later. For version 2.0.0, consider upgrading to a newer version as this version is end-of-life.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6052

Affected Products

Checkmk