Posted by SBA Research Security Advisory via Fulldisclosure on Oct 13
# Checkmk Path Traversal #
## Vulnerability Overview ##
Checkmk in versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since
version 2.1.0b1 is prone to a path traversal vulnerability in the report
scheduler. Due to an insufficient validation of a file name input, users can
store reports in arbitrary locations on the server.
*…
– Read More – Full Disclosure



