Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6f3j-vw42-8645

Опубликовано: 08 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 5.4

Описание

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.

EPSS

Процентиль: 3%
0.00136
Низкий

8.5 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.

CVSS3: 5.4
nvd
около 2 месяцев назад

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.

CVSS3: 5.4
debian
около 2 месяцев назад

Stored cross-site scripting in the URL dashboard widget in Checkmk <2. ...

EPSS

Процентиль: 3%
0.00136
Низкий

8.5 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79