Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-21231
HistoryFeb 23, 2022 - 12:00 a.m.

Checkmk Cross-Site Scripting Vulnerability (CNVD-2022-21231)

2022-02-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
checkmk
cross-site scripting
vulnerability
user properties
html injection
version 2.0.0p19
client-side code
cnvd-2022-21231

EPSS

0.001

Percentile

31.3%

Checkmk is an editor. A cross-site scripting vulnerability exists in Checkmk, which stems from Checkmk version <= 2.0.0p19. When creating or editing user properties, Help Text is affected by HTML injection, which can be triggered when editing a user. An attacker could use this vulnerability to execute client-side code.

EPSS

0.001

Percentile

31.3%