Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-11-09T22:28:52
Updated: 2024-08-04T00:40:47.244Z
Reserved: 2021-06-24T00:00:00
Link: CVE-2021-35489
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-09T23:15:08.830
Modified: 2024-11-21T06:12:21.887
Link: CVE-2021-35489
Redhat
No data.