A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.
References
Link | Resource |
---|---|
http://git.mathias-kettner.de/git/?p=check_mk.git;a=blob;f=.werks/4757;hb=c248f0b6ff7b15ced9f07a3df8a80fad656ea5b1 | Third Party Advisory |
https://www.tenable.com/security/research/tra-2017-21 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-06-21 11:29
Updated : 2019-04-22 09:55
NVD link : CVE-2017-9781
Mitre link : CVE-2017-9781
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
check_mk_project
- check_mk