Vulnerabilities
Products Security index
Vulnerabilities
CVE-2024-23822
Thruk Incorrect limitation of a pathname to a restricted directory (Path Traversal) (CWE-22)
CVE-2023-34096
Thruk has Path Traversal Vulnerability in panorama.pm
CVE-2021-35490
Thruk before 2.44 allows XSS for a quick command.
CVE-2021-35488
Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.
CVE-2021-35489
Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.
