CVE 8.5 HIGH

Cross Site Scripting through compromised remote site_CVE-2025-39663

8.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).

AI Analysis

Cross-Site Scripting vulnerability in Checkmk's distributed monitoring

Basic Information

ID CVE-2025-39663
Source Checkmk
Published Oct 30, 2025 at 10:43
Modified Oct 30, 2025 at 13:25

Affected Product

Vendor Checkmk GmbH
Product Checkmk
Version 2.4.0
Affected Versions Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
Checkmk GmbH Checkmk 2.1.0

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Checkmk GmbH
Product Checkmk
Version 2.4.0, 2.3.0, 2.2.0, 2.1.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.