Home

Description

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML logs, which can then be accessed via a crafted phishing link.

PUBLISHED Reserved 2025-11-12 | Published 2026-02-26 | Updated 2026-02-26 | Assigner Checkmk




HIGH: 7.3CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

2.4.0 (semver) before 2.4.0p22
affected

2.3.0 (semver) before 2.3.0p43
affected

Credits

Lisa Gnedt (SBA Research) reporter

References

checkmk.com/werk/19238 vendor-advisory

cve.org (CVE-2025-64999)

nvd.nist.gov (CVE-2025-64999)

Download JSON