In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).
2022-02-24T15:15:29.553
2024-11-21T06:50:40.187
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 1.6.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.0.0 | Yes |