CVE-2021-35488 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Thruk affects v. 2.40-2.


Thruk is an open-source monitoring platform utilized for monitoring multiple servers and network services. It is designed to provide an intuitive and modern web interface for centralized monitoring. Thruk facilitates effortless monitoring of critical systems and services, enabling system administrators and IT professionals to detect, diagnose, and rectify errors or issues promptly.

The CVE-2021-35488 vulnerability is a reflected cross-site scripting (XSS) vulnerability identified in Thruk version 2.40-2. The vulnerability is triggered through the host or title parameter of the /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE} URL. An attacker can leverage this vulnerability to inject malicious JavaScript code into the status.cgi page, compromising the security of the system.

When exploited, the CVE-2021-35488 vulnerability permits attackers to execute arbitrary JavaScript code in the context of an authenticated user's browser. This can enable them to perform unauthorized actions on the system, compromise sensitive data, or even launch more advanced attacks like session hijacking or cookie theft. The potential risks of such attacks can be severe, and their impact on the affected user and the organization can be wide-ranging.

