← Back

CVE-2021-40906

nvd nist
Published: Mar 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.

Affected (37)

1 product
Checkmk
1 product
Checkmk
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Checkmk
From 1.5.0 to 1.6.0
Version 1.6.0
Version 1.6.0 b10
Version 1.6.0 b12
Version 1.6.0 b1
Version 1.6.0 b3
Version 1.6.0 b4
Version 1.6.0 b5
Version 1.6.0 b9
Version 1.6.0 p10
Version 1.6.0 p11
Version 1.6.0 p12
Version 1.6.0 p13
Version 1.6.0 p14
Version 1.6.0 p15
Version 1.6.0 p16
Version 1.6.0 p19
Version 1.6.0 p1
Version 1.6.0 p20
Version 1.6.0 p21
Version 1.6.0 p22
Version 1.6.0 p23
Version 1.6.0 p24
Version 1.6.0 p25
Version 1.6.0 p2
Version 1.6.0 p3
Version 1.6.0 p4
Version 1.6.0 p5
Version 1.6.0 p6
Version 1.6.0 p7
Version 1.6.0 p8
Version 1.6.0 p9
Tribe29
Version 1.6.0b10
Version 1.6.0b11
Version 1.6.0p10
Version 1.6.0p17
Version 1.6.0p18

References (4)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.