← Back

CVE-2014-5338

nvd nist
Published: Aug 22, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) render_status_icons function in htmllib.py or (2) ajax_action function in actions.py.

Affected (7)

Check Mk
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Check Mk Project
Version 1.2.4
Version 1.2.4 p1
Version 1.2.4 p2
Version 1.2.4 p3
Version 1.2.5 i1
Version 1.2.5 i2
Version 1.2.5 i3

Timeline

No history available yet.