Beveiligingsadvies

CVE-2024-28832

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-25 11:45:33
Laatst bijgewerkt 2024-08-02 00:56:58
Toegewezen door Checkmk
CVSS-score 4.8
Status PUBLISHED

Beschrijving

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.