Lucene search

K
osvGoogleOSV:CVE-2021-40904
HistoryMar 25, 2022 - 11:15 p.m.

CVE-2021-40904

2022-03-2523:15:08
Google
osv.dev
3
checkmk raw edition
dokuwiki
remote code execution
web management interface
valid credentials
administrator

AI Score

7.8

Confidence

Low

EPSS

0.007

Percentile

80.3%

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

AI Score

7.8

Confidence

Low

EPSS

0.007

Percentile

80.3%