Vulnerability Description
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | <= 2.0.0 |
Related Weaknesses (CWE)
References
- https://checkmk.com/werk/17024Vendor Advisory
- https://checkmk.com/werk/17024Vendor Advisory
FAQ
What is CVE-2024-28832?
CVE-2024-28832 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injec...
How severe is CVE-2024-28832?
CVE-2024-28832 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28832?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk.