Lucene search

K
vulnrichmentCheckmkVULNRICHMENT:CVE-2024-28831
HistoryJun 25, 2024 - 11:45 a.m.

CVE-2024-28831 XSS in confirmation pop-up

2024-06-2511:45:27
CWE-80
Checkmk
github.com
4
xss
stored xss
confirmation pop-up
user input
checkmk
arbitrary scripts
html elements
security vulnerability

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.3

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.

CNA Affected

[
  {
    "vendor": "Checkmk GmbH",
    "product": "Checkmk",
    "versions": [
      {
        "status": "affected",
        "version": "2.3.0",
        "lessThan": "2.3.0p7",
        "versionType": "semver"
      },
      {
        "status": "affected",
        "version": "2.2.0",
        "lessThan": "2.2.0p28",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.3

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-28831