XSS in Crash Report Page
Vulnerability Description
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28832
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- PS Positive Security GmbH
References
More from Checkmk GmbH
View All →Affected Vendor
Checkmk GmbH
View all reports →