CVE-2022-46836: PHP code injection in watolib
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46836?
CVE-2022-46836 is considered a critical vulnerability due to its potential for remote code execution via PHP code injection.
How do I fix CVE-2022-46836?
To fix CVE-2022-46836, upgrade your Checkmk installation to a version later than 2.1.0p10, 2.0.0p27, or 1.6.0p29.
What versions are affected by CVE-2022-46836?
CVE-2022-46836 affects Checkmk versions 2.1.0 up to and including 2.1.0p10, 2.0.0 up to and including 2.0.0p27, and 1.6.0 up to and including 1.6.0p29.
What are the potential impacts of CVE-2022-46836?
Exploitation of CVE-2022-46836 allows attackers to inject and execute arbitrary PHP code, potentially leading to full system compromise.
Is there a known exploit for CVE-2022-46836?
Yes, there are reports indicating that CVE-2022-46836 has been actively exploited in the wild.