CVE-2022-24566

In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).
CVSS

No CVSS.

References
Configurations

No configuration.

Information

Published : 2022-02-24 15:15

Updated : 2022-02-24 16:02


NVD link : CVE-2022-24566

Mitre link : CVE-2022-24566


JSON object : View

Products Affected

No product.

CWE

No CWE.