First published: Wed Jun 21 2017(Updated: )
A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Check Mk Project Check Mk | =1.4.0 | |
Check Mk Project Check Mk | =1.4.0-p1 | |
Check Mk Project Check Mk | =1.4.0-p2 | |
Check Mk Project Check Mk | =1.4.0-p3 | |
Check Mk Project Check Mk | =1.4.0-p4 | |
Check Mk Project Check Mk | =1.4.0-p5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.