The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
History

Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00031}

epss

{'score': 0.0004}


Thu, 06 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Feb 2025 01:30:00 +0000


Tue, 04 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Description The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
Title Checkmk NagVis Reflected Cross-site Scripting
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: KoreLogic

Published: 2025-02-04T22:04:00.315Z

Updated: 2025-11-03T19:29:15.962Z

Reserved: 2025-01-24T18:22:32.696Z

Link: CVE-2024-13722

cve-icon Vulnrichment

Updated: 2025-11-03T19:29:15.962Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-04T22:15:40.113

Modified: 2025-11-03T20:16:08.400

Link: CVE-2024-13722

cve-icon Redhat

No data.