CVE-2024-13722: Checkmk NagVis Reflected Cross-site Scripting
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13722?
CVE-2024-13722 is considered a critical vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-13722?
To remediate CVE-2024-13722, update the Checkmk NagVis component to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-13722?
CVE-2024-13722 affects both authenticated and unauthenticated users of the NagVis component within Checkmk.
What type of vulnerability is CVE-2024-13722?
CVE-2024-13722 is a reflected cross-site scripting (XSS) vulnerability that can run arbitrary JavaScript in user browsers.
Can I be attacked through CVE-2024-13722 even if I am not logged in?
Yes, CVE-2024-13722 allows an attacker to exploit the vulnerability on both authenticated and unauthenticated users.