← back
CVE-2022-23961mediumobserved exploitationCWE-79

CVE-2022-23961

35Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 6.1epss 0.2%
from disclosure to weapon
Published on NVDMay 8
VulnCheckDec 31
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
yesVulnCheck
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
n/a · n/a