CVE-2024-38859

MEDIUM

Checkmk < 2.3.0p14, < 2.2.0p33, < 2.1.0p47 - Stored Cross-Site Scripting in SLA Column Title

Title source: llm
STIX 2.1

Description

XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0042
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
checkmk/checkmk 2.0.0
checkmk/checkmk 2.1.0 (49 CPE variants)
Published Aug 26, 2024
Tracked Since Feb 18, 2026