CVE-2024-13722 Details
Description
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
A reflected cross-site scripting vulnerability has been identified in the NagVis component of Checkmk, specifically in Checkmk version 2.3.0p2 and NagVis version 1.9.40. This vulnerability allows an attacker to inject and execute arbitrary JavaScript in the context of the user's browser. The issue arises when the 'members' body parameter is processed by 'std_table.php' without proper validation, enabling the injection of malicious scripts that execute upon delivery.
Users can upgrade to Checkmk 2.3.0p10 or NagVis 1.9.42, both released on July 15, 2024, to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 4, 2025CISA-ADP
Assessed Feb 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://korelogic.com/Resources/Advisories/KL-001-2025-001.txt | CISA-ADP | AdvisoryExploitRemedy |
| http://seclists.org/fulldisclosure/2025/Feb/3 | CVE | AdvisoryExploitMailing ListRemedy |
| https://lists.debian.org/debian-lts-announce/2025/05/msg00000.html | CVE | |
| http://www.openwall.com/lists/oss-security/2025/02/04/3 | CVE | AdvisoryExploitMailing ListRemedy |
| https://checkmk.com/werks?version=2.3.0p10 | KoreLogic | Release NotesVendor |
| https://korelogic.com/Resources/Advisories/KL-001-2025-001.txt | KoreLogic | AdvisoryExploitRemedy |
| https://www.nagvis.org/downloads/changelog/1.9.42 | KoreLogic | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | KoreLogic |
Affected Products
| Product | Versions |
|---|---|
| Checkmk | 2.3.0p2 |
CPE
Remediation
| |
| Checkmk NagVis | 1.9.40 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | KoreLogic |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Feb 5, 2025 | CVE Modified | CVE |
| Feb 4, 2025 | New CVE Received | KoreLogic |
Volerion