Lucene search

K
cvelistMitreCVELIST:CVE-2021-35489
HistoryNov 09, 2021 - 10:28 p.m.

CVE-2021-35489

2021-11-0922:28:52
mitre
www.cve.org

0.001 Low

EPSS

Percentile

37.0%

Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.

0.001 Low

EPSS

Percentile

37.0%

Related for CVELIST:CVE-2021-35489