Loading HuntDB...

GHSA-5554-3cr8-7rwc

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.

Related CVEs

Key Information

GHSA ID
GHSA-5554-3cr8-7rwc
Published
August 26, 2024 3:31 PM
Last Modified
December 3, 2024 6:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 13, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.