Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.
References
Link Resource
https://www.gruppotim.it/redteam Exploit Third Party Advisory
https://www.thruk.org/changelog.html Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-11-09T22:29:41

Updated: 2021-11-09T22:29:41

Reserved: 2021-06-24T00:00:00


Link: CVE-2021-35488

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-11-09T23:15:08.787

Modified: 2021-11-10T19:02:39.203


Link: CVE-2021-35488

JSON object: View

cve-icon Redhat Information

No data.

CWE