VDB
CVE-2014-5338
CVE-2014-5338
PUBLISHED
Reported by mitre · Published August 22, 2014
Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) render_status_icons function in htmllib.py or (2) ajax_action function in actions.py.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Aug 22, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 20140820 Deutsche Telekom CERT Advisory [DTC-A-20140820-001] check_mk vulnerabilities mailing-listx_refsource_BUGTRAQ
- x_refsource_CONFIRM
- 69312 vdb-entryx_refsource_BID
- RHSA-2015:1495 vendor-advisoryx_refsource_REDHAT
- x_refsource_MISC
- checkmk-cve20145338-xss(95383) vdb-entryx_refsource_XF