The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
References
Configurations
No configuration.
History
06 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
References | () https://korelogic.com/Resources/Advisories/KL-001-2025-001.txt - | |
Summary |
|
05 Feb 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-04 22:15
Updated : 2025-02-06 15:15
NVD link : CVE-2024-13722
Mitre link : CVE-2024-13722
CVE.ORG link : CVE-2024-13722
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')