Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
References
Link | Resource |
---|---|
https://checkmk.com/werk/17024 | |
https://checkmk.com/werk/17024 |
Configurations
No configuration.
History
21 Nov 2024, 09:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://checkmk.com/werk/17024 - | |
Summary |
|
25 Jun 2024, 12:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-25 12:15
Updated : 2024-11-21 09:07
NVD link : CVE-2024-28832
Mitre link : CVE-2024-28832
CVE.ORG link : CVE-2024-28832
JSON object : View
Products Affected
No product.
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)