Home

Description

In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.

PUBLISHED Reserved 2022-01-26 | Published 2026-05-08 | Updated 2026-05-08 | Assigner mitre

References

herolab.usd.de/security-advisories/usd-2021-0034/ exploit

herolab.usd.de/security-advisories/

herolab.usd.de/security-advisories/usd-2021-0034/

cve.org (CVE-2022-23961)

nvd.nist.gov (CVE-2022-23961)

Download JSON