CVE-2022-24564

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.
References
Link Resource
https://checkmk.com/werk/13199 Patch Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tribe29:checkmk:2.0.0:-:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b3:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b4:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b5:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b6:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b7:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:b8:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:i1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p10:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p11:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p12:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p13:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p14:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p15:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p16:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p17:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p18:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:2.0.0:p19:*:*:*:*:*:*

Information

Published : 2022-02-21 15:15

Updated : 2022-03-02 08:38


NVD link : CVE-2022-24564

Mitre link : CVE-2022-24564


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

tribe29

  • checkmk