Back to Database
Status published
Low
CVE-2024-38858
Cross-site scripting in Robotmk logs view
Vulnerability Description
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-38858
Credits & Attribution
No credits recorded in the NVD database.
References
More from Checkmk GmbH
View All →CVE-2025-65000
Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule
Low
2.3
CVE-2025-64999
Cross-site scripting in HTML logs of Synthetic Monitoring test services
High
7.3
CVE-2025-64998
Session hijacking via exposed session signing secret in distributed Checkmk setups
High
7.3
CVE-2025-64997
Insufficient permission validation when showing agent information
Medium
6.3
CVE-2025-64996
Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's output
Medium
4.8
Affected Vendor
Checkmk GmbH
View all reports →Affected Software
Checkmk
Vulnerable Versions:
2.3.0
Timeline
Official Publish:
September 2nd, 2024
Last Modified:
September 3rd, 2024
Added to House:
July 22nd, 2026