Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).
History

Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Checkmk
Checkmk checkmk
Vendors & Products Checkmk
Checkmk checkmk

Thu, 30 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 10:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).
Title Cross Site Scripting through compromised remote site
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2025-10-30T10:43:08.500Z

Updated: 2025-10-30T13:25:58.384Z

Reserved: 2025-04-16T07:07:38.256Z

Link: CVE-2025-39663

cve-icon Vulnrichment

Updated: 2025-10-30T13:25:45.664Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T11:15:32.400

Modified: 2025-10-30T15:03:13.440

Link: CVE-2025-39663

cve-icon Redhat

No data.