herolab.usd.de
https://herolab.usd.de/security-advisories CVE-2022-23961
MEDIUM
Thruk Monitoring reflected XSS
Record summary
CVE-2022-23961 has a selected CVSS score of 6.1 (medium).
Description
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 31, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Thruk MonitoringBrowse Thruk Monitoring / Thruk Monitoring | VulnCheck | Version data not supplied | |
References
3herolab.usd.de
https://herolab.usd.de/security-advisories/usd-2021-0034 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-23961