CVE-2024-28832

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
Configurations

No configuration.

History

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://checkmk.com/werk/17024 - () https://checkmk.com/werk/17024 -
Summary
  • (es) XSS almacenado en la página Informe de fallos en Checkmk antes de las versiones 2.3.0p7, 2.2.0p28, 2.1.0p45 y 2.0.0 (EOL) permite a los usuarios con permiso para cambiar la configuración global para ejecutar scripts arbitrarios inyectando elementos HTML en la URL del informe de fallos en la configuración global.

25 Jun 2024, 12:24

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-25 12:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-28832

Mitre link : CVE-2024-28832

CVE.ORG link : CVE-2024-28832


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)