Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-13723
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
0
Attacker Value
Unknown
CVE-2024-13722
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
0
Attacker Value
Unknown
CVE-2024-47093
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
0
Attacker Value
Unknown
CVE-2023-46287
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.
0
Attacker Value
Unknown
CVE-2022-46945
Disclosure Date: May 26, 2023 (last updated November 04, 2023)
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
0
Attacker Value
Unknown
CVE-2022-3979
Disclosure Date: November 13, 2022 (last updated February 24, 2025)
A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to incorrect type conversion. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 1.9.34 is able to address this issue. The identifier of the patch is 7574fd8a2903282c2e0d1feef5c4876763db21d5. It is recommended to upgrade the affected component. The identifier VDB-213557 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-33178
Disclosure Date: October 14, 2021 (last updated February 23, 2025)
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.
0
Attacker Value
Unknown
CVE-2017-6393
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0