Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-35489
HistoryNov 09, 2021 - 11:15 p.m.

Cross site scripting

2021-11-0923:15:00
PRIOn knowledge base
www.prio-n.com

0.001 Low

EPSS

Percentile

37.0%

Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.

CPENameOperatorVersion
thrukeq2.40.2

0.001 Low

EPSS

Percentile

37.0%

Related for PRION:CVE-2021-35489