Back to search
CVE-2014-5338
Published: Aug 22, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) render_status_icons function in htmllib.py or (2) ajax_action function in actions.py.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20140820 Deutsche Telekom CERT Advisory [DTC-A-20140820-001] check_mk vulnerabilities
mailing-list
x_refsource_BUGTRAQ
http://mathias-kettner.de/check_mk_werks.php?werk_id=0982&HTML=yes
x_refsource_CONFIRM
69312
vdb-entry
x_refsource_BID
RHSA-2015:1495
vendor-advisory
x_refsource_REDHAT
checkmk-cve20145338-xss(95383)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now