CVE-2024-28832

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
References
Configurations

No configuration.

History

25 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-25 12:15

Updated : 2024-06-25 12:24


NVD link : CVE-2024-28832

Mitre link : CVE-2024-28832

CVE.ORG link : CVE-2024-28832


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)