Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2021-11-09T22:28:52
Updated: 2024-08-04T00:40:47.244Z
Reserved: 2021-06-24T00:00:00
Link: CVE-2021-35489

No data.

Status : Modified
Published: 2021-11-09T23:15:08.830
Modified: 2024-11-21T06:12:21.887
Link: CVE-2021-35489

No data.