XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.
References
History

Mon, 26 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.
Title XSS in view page with SLA column
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2024-08-26T14:15:32.555Z

Updated: 2024-08-26T15:22:30.830Z

Reserved: 2024-06-20T10:03:09.178Z

Link: CVE-2024-38859

cve-icon Vulnrichment

Updated: 2024-08-26T15:22:27.059Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-26T15:15:08.183

Modified: 2024-08-26T15:15:23.727

Link: CVE-2024-38859

cve-icon Redhat

No data.