Security Advisory

CVE-2017-9781

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-06-21 18:00:00
Last updated 2024-08-05 17:18:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.