Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
2024-06-25T12:15:09.713
2024-12-04T16:15:21.077
Analyzed
CVSSv3.1: 4.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | checkmk | checkmk | ≤ 2.0.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.1.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.2.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |
| Application | checkmk | checkmk | 2.3.0 | Yes |