{"id":"CVE-2017-9781","details":"A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.","modified":"2026-08-27T08:15:05.259046Z","published":"2017-06-21T18:29:00.387Z","references":[{"type":"WEB","url":"http://git.mathias-kettner.de/git/?p=check_mk.git%3Ba=blob%3Bf=.werks/4757%3Bhb=c248f0b6ff7b15ced9f07a3df8a80fad656ea5b1"},{"type":"EVIDENCE","url":"https://www.tenable.com/security/research/tra-2017-21"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/Checkmk/checkmk","events":[{"introduced":"3144d0a38c9ff1b290ae6f4489c5df34a2daaf65"},{"last_affected":"b2fba42409c49b7ac589ce84301ce659b9373349"}],"database_specific":{"cpe":["cpe:2.3:a:check_mk_project:check_mk:1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:check_mk_project:check_mk:1.4.0:p1:*:*:*:*:*:*","cpe:2.3:a:check_mk_project:check_mk:1.4.0:p2:*:*:*:*:*:*","cpe:2.3:a:check_mk_project:check_mk:1.4.0:p3:*:*:*:*:*:*","cpe:2.3:a:check_mk_project:check_mk:1.4.0:p4:*:*:*:*:*:*","cpe:2.3:a:check_mk_project:check_mk:1.4.0:p5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.4.0"},{"last_affected":"1.4.0"},{"introduced":"1.4.0-p1"},{"last_affected":"1.4.0-p1"},{"introduced":"1.4.0-p2"},{"last_affected":"1.4.0-p2"},{"introduced":"1.4.0-p3"},{"last_affected":"1.4.0-p3"},{"introduced":"1.4.0-p4"},{"last_affected":"1.4.0-p4"},{"introduced":"1.4.0-p5"},{"last_affected":"1.4.0-p5"}],"source":"CPE_STRING"}}],"versions":["1.4.0","1.4.0-p1","1.4.0-p2","1.4.0-p3","1.4.0-p4","1.4.0-p5","v1.4.0p5","v1.4.0p4","v1.4.0p3","v1.4.0p2","v1.4.0p1","v1.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9781.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}