8.5

CVE-2025-39663

Medienbericht
Exploit

Cross Site Scripting through compromised remote site

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CheckmkCheckmk Version >= 2.0.0 < 2.3.0
CheckmkCheckmk Version2.3.0 Update-
CheckmkCheckmk Version2.3.0 Updatep1
CheckmkCheckmk Version2.3.0 Updatep10
CheckmkCheckmk Version2.3.0 Updatep11
CheckmkCheckmk Version2.3.0 Updatep12
CheckmkCheckmk Version2.3.0 Updatep13
CheckmkCheckmk Version2.3.0 Updatep14
CheckmkCheckmk Version2.3.0 Updatep15
CheckmkCheckmk Version2.3.0 Updatep16
CheckmkCheckmk Version2.3.0 Updatep17
CheckmkCheckmk Version2.3.0 Updatep18
CheckmkCheckmk Version2.3.0 Updatep19
CheckmkCheckmk Version2.3.0 Updatep2
CheckmkCheckmk Version2.3.0 Updatep20
CheckmkCheckmk Version2.3.0 Updatep21
CheckmkCheckmk Version2.3.0 Updatep22
CheckmkCheckmk Version2.3.0 Updatep23
CheckmkCheckmk Version2.3.0 Updatep24
CheckmkCheckmk Version2.3.0 Updatep25
CheckmkCheckmk Version2.3.0 Updatep26
CheckmkCheckmk Version2.3.0 Updatep27
CheckmkCheckmk Version2.3.0 Updatep28
CheckmkCheckmk Version2.3.0 Updatep29
CheckmkCheckmk Version2.3.0 Updatep3
CheckmkCheckmk Version2.3.0 Updatep30
CheckmkCheckmk Version2.3.0 Updatep31
CheckmkCheckmk Version2.3.0 Updatep32
CheckmkCheckmk Version2.3.0 Updatep33
CheckmkCheckmk Version2.3.0 Updatep34
CheckmkCheckmk Version2.3.0 Updatep35
CheckmkCheckmk Version2.3.0 Updatep36
CheckmkCheckmk Version2.3.0 Updatep37
CheckmkCheckmk Version2.3.0 Updatep38
CheckmkCheckmk Version2.3.0 Updatep4
CheckmkCheckmk Version2.3.0 Updatep5
CheckmkCheckmk Version2.3.0 Updatep6
CheckmkCheckmk Version2.3.0 Updatep7
CheckmkCheckmk Version2.3.0 Updatep8
CheckmkCheckmk Version2.3.0 Updatep9
CheckmkCheckmk Version2.4.0 Update-
CheckmkCheckmk Version2.4.0 Updatep1
CheckmkCheckmk Version2.4.0 Updatep10
CheckmkCheckmk Version2.4.0 Updatep11
CheckmkCheckmk Version2.4.0 Updatep12
CheckmkCheckmk Version2.4.0 Updatep13
CheckmkCheckmk Version2.4.0 Updatep2
CheckmkCheckmk Version2.4.0 Updatep3
CheckmkCheckmk Version2.4.0 Updatep4
CheckmkCheckmk Version2.4.0 Updatep5
CheckmkCheckmk Version2.4.0 Updatep6
CheckmkCheckmk Version2.4.0 Updatep7
CheckmkCheckmk Version2.4.0 Updatep9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.419
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.4 1.7 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
security@checkmk.com 8.5 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.10.2025 14:31
https://checkmk.com/werk/17998
Vendor Advisory
https://github.com/sbaresearch/advisories/tree/82fd27e4570433464c30b35150b197db9a850f4e/2025/SBA-ADV-20250729-01_Checkmk_Cross_Site_Scripting
Third Party Advisory
Exploit
http://seclists.org/fulldisclosure/2025/Nov/0
Third Party Advisory
Exploit
Mailing List