CVE-2024-38859
XSS in view page with SLA column
Severity Score
4.8
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-06-20 CVE Reserved
- 2024-08-26 CVE Published
- 2024-08-26 CVE Updated
- 2024-08-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CAPEC
- CAPEC-592: Stored XSS
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.3.0 < 2.3.0p14 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.3.0 < 2.3.0p14" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.2.0 < 2.2.0p33 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.2.0 < 2.2.0p33" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.1.0 < 2.1.0p47 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.1.0 < 2.1.0p47" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.0.0 <= 2.0.0p39 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.0.0 <= 2.0.0p39" | en |
Affected
|