CVE-2024-28831: XSS in confirmation pop-up
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0p7 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.2.0p28
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28831?
The severity of CVE-2024-28831 is classified as high due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-28831?
To fix CVE-2024-28831, update Checkmk to versions 2.3.0p7 or 2.2.0p28 or later.
What software is affected by CVE-2024-28831?
CVE-2024-28831 affects Checkmk versions earlier than 2.3.0p7 and 2.2.0p28.
What type of vulnerability is CVE-2024-28831?
CVE-2024-28831 is a stored cross-site scripting (XSS) vulnerability.
Can CVE-2024-28831 be exploited remotely?
Yes, CVE-2024-28831 can be exploited remotely by users who can inject malicious scripts into confirmation pop-ups.