Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hc7p-6r8x-vr4q

Опубликовано: 08 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 5.4

Описание

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.

EPSS

Процентиль: 4%
0.0014
Низкий

8.5 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.

CVSS3: 5.4
nvd
около 2 месяцев назад

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.

CVSS3: 5.4
debian
около 2 месяцев назад

Improper neutralization of HTML-encoded characters in the URL validati ...

EPSS

Процентиль: 4%
0.0014
Низкий

8.5 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79