CVE-2017-9781: XSS
Published Jun 21, 2017
·Updated
A cross site scripting (XSS) vulnerability exists in CheckMK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.
Affected Software
6 affected components
Check Mk Project Check Mk=1.4.0
Check Mk Project Check Mk=1.4.0-p1
Check Mk Project Check Mk=1.4.0-p2
Check Mk Project Check Mk=1.4.0-p3
Check Mk Project Check Mk=1.4.0-p4
Check Mk Project Check Mk=1.4.0-p5
Event History
Jun 21, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9781?
CVE-2017-9781 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-9781?
To mitigate CVE-2017-9781, upgrade Check_MK to version 1.4.0p6 or later.
3
Who is affected by CVE-2017-9781?
CVE-2017-9781 affects Check_MK versions 1.4.0 prior to 1.4.0p6.
4
What type of vulnerability is CVE-2017-9781?
CVE-2017-9781 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2017-9781 be exploited remotely?
Yes, CVE-2017-9781 can be exploited by an unauthenticated remote attacker.