Page 3 of 34 results (0.002 seconds)

CVSS: 4.8EPSS: 0%CPEs: 4EXPL: 0

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings. • https://checkmk.com/werk/17024 • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL) • https://checkmk.com/werk/17009 • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server. La restricción inadecuada de las rutas de carga y descarga locales en check_sftp en Checkmk anterior a 2.3.0p4, 2.2.0p27, 2.1.0p44 y en Checkmk 2.0.0 (EOL) permite a atacantes con permisos suficientes configurar la verificación para leer y escribir archivos locales en el servidor del sitio Checkmk. • https://checkmk.com/werk/15200 • CWE-73: External Control of File Name or Path •

CVSS: 5.9EPSS: 0%CPEs: 4EXPL: 0

Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing. La restricción inadecuada de intentos de autenticación excesivos en algunos métodos de autenticación en Checkmk anteriores a 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43 y en Checkmk 2.0.0 (EOL) facilita la fuerza bruta de contraseñas. • https://checkmk.com/werk/15198 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc La inyección de argumentos en el complemento del agente websphere_mq en Checkmk 2.0.0, 2.1.0, &lt;2.2.0p25 y &lt;2.3.0b5 permite a un atacante local inyectar un argumento para ejecutar mqsc • https://checkmk.com/werk/16615 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data •