← Retour à la recherche de CVE

CVE-2026-8078

Checkmk

Description

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users- browsers when they view the Activate Changes page or Audit log.

CVSS 4.8EPSS 0.14300000000000002%Risque 0.49
Voir la source
Publication
2026-06-08 13:16:33
Versions concernées
cannotmatch
Type
Installed app
Dernière modification
2026-07-23 07:10:00
Vecteur
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N