VYPR

CheckMK Raw Edition

by Checkmk

CVEs (2)

  • CVE-2021-40904HigMar 25, 2022
    risk 0.57cvss 8.8epss 0.03

    The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the…

  • CVE-2021-40906MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as…