The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 06 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 05 Feb 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users. | |
| Title | Checkmk NagVis Reflected Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: KoreLogic
Published: 2025-02-04T22:04:00.315Z
Updated: 2025-11-03T19:29:15.962Z
Reserved: 2025-01-24T18:22:32.696Z
Link: CVE-2024-13722
Updated: 2025-11-03T19:29:15.962Z
Status : Awaiting Analysis
Published: 2025-02-04T22:15:40.113
Modified: 2025-11-03T20:16:08.400
Link: CVE-2024-13722
No data.