Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-22309: Reflected Cross Site Scripting (XSS)

Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.

CVE
#xss#vulnerability#web

Component

Firmware

Title

Reflected Cross Site Scripting (XSS)

Date

Apr 4, 2023

Appliance Version

1.6.4

Level

Trivial Change

Class

Bug Fix

Compatibility

Compatible - no manual interaction needed

Prior to this Werk an attacker could send malicious links to unsuspecting users in order to inject malicious HTML code into the browser of the user.

This vulnerability was identified through a commissioned penetration test conducted by OPTIMAbit (Roman Mueller).

Vulnerability Management: We have rated the issue with a CVSS Score of 6.1 (Medium) with the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. We assigned CVE-2023-22309 to this vulnerability.

Changes: This Werk adds escaping to URL parameter keys.

To the list of all Werks

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907