216.73.216.6

CVE-2025-39663

· Published 30/10/2025 11:15 · Modified 30/10/2025 15:03

Labels: CVE-2025-39663 2025-10-30CVE-2025-39663CWE-80[email protected]

Essential information

Published
30/10/2025 11:15
Modified
30/10/2025 15:03
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:<2.4.0:p14:*:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.3.0:p39:*:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*

References