CVE-2024-28832

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
References
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-25 12:15

Updated : 2024-06-25 12:24


NVD link : CVE-2024-28832

Mitre link : CVE-2024-28832

CVE.ORG link : CVE-2024-28832


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)