CVE-2020-28919
- EPSS 1.08%
- Veröffentlicht 15.01.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:23:17
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
CVE-2021-36563
- EPSS 1.72%
- Veröffentlicht 26.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:49
The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as Jav...
CVE-2020-24908
- EPSS 0.3%
- Veröffentlicht 19.02.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:16:11
Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
CVE-2017-14955
- EPSS 12.13%
- Veröffentlicht 02.10.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.