Checkmk
cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*
- < 2.5.0b4
A livestatus injection vulnerability has been identified in the monitoring quicksearch feature of Checkmk versions prior to 2.5.0b4. This vulnerability allows authenticated attackers to inject livestatus commands through the search query, exploiting inadequate input sanitization in the search filter plugins.
Exploitation of this vulnerability allows for livestatus command injection, which could potentially be used to manipulate monitoring data or behavior.
Users can upgrade to Checkmk versions 2.6.0b1 or 2.5.0b4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.