Vulnerability Description
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | 2.0.0 |
| Tribe29 | Checkmk | >= 1.6.0, < 2.0.0 |
Related Weaknesses (CWE)
References
- https://checkmk.com/werk/15069Vendor Advisory
- https://checkmk.com/werk/15069Vendor Advisory
FAQ
What is CVE-2023-22288?
CVE-2023-22288 is a vulnerability with a CVSS score of 4.1 (MEDIUM). HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
How severe is CVE-2023-22288?
CVE-2023-22288 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22288?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk, Tribe29 Checkmk.