CVE-2024-6052: XSS in SQL check parameters
Stored XSS in Checkmk before versions 2.3.0p10, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0p8 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.2.0p29 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.1.0p45 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6052?
CVE-2024-6052 has a severity rating that warrants immediate attention due to its potential for stored XSS attacks.
How do I fix CVE-2024-6052?
To fix CVE-2024-6052, update Checkmk to versions 2.3.0p10, 2.2.0p29, or 2.1.0p45 or later.
What types of attacks can CVE-2024-6052 enable?
CVE-2024-6052 can enable attackers to execute arbitrary scripts, leading to stored XSS vulnerabilities.
Which versions of Checkmk are affected by CVE-2024-6052?
CVE-2024-6052 affects Checkmk versions prior to 2.3.0p10, 2.2.0p29, 2.1.0p45, and 2.0.0.
Can CVE-2024-6052 be exploited remotely?
Yes, CVE-2024-6052 can be exploited remotely if an attacker injects malicious HTML into the Checkmk application.