← Back to CVE search

CVE-2022-23961

Thruk Monitoring

Description

In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.

CVSS 6.1EPSS 0.201%Risk 0.62
View source
Published
2026-05-08 05:16:08
Affected versions
<=2.46.3
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N