Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
References
History

Tue, 17 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 14:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
Title Reflected links in error message facilitate phishing attacks
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2024-09-17T14:01:09.555Z

Updated: 2024-09-17T17:16:28.885Z

Reserved: 2024-06-20T10:03:09.178Z

Link: CVE-2024-38860

cve-icon Vulnrichment

Updated: 2024-09-17T17:15:45.708Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-17T14:15:17.347

Modified: 2024-09-20T12:30:51.220

Link: CVE-2024-38860

cve-icon Redhat

No data.