Products
Checkmk
- before 2.3.0p16
- before 2.2.0p34
Source
security@checkmk.com
Tags
CVE-2024-38860 details
Published : Sept. 17, 2024, 2:15 p.m.
Last Modified : Sept. 17, 2024, 2:15 p.m.
Last Modified : Sept. 17, 2024, 2:15 p.m.
Description
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
References
URL | Source |
---|---|
https://checkmk.com/werk/17094 | security@checkmk.com |
This website uses the NVD API, but is not approved or certified by it.