Vulnerability Database

309,136

Total vulnerabilities in the database

CVE-2021-40906

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.

  • Published: Mar 25, 2022
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-40906
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
tribe29 / checkmk 1.6.0b10 1.6.0b10.x
tribe29 / checkmk 1.6.0b11 1.6.0b11.x
tribe29 / checkmk 1.6.0p10 1.6.0p10.x
tribe29 / checkmk 1.6.0p17 1.6.0p17.x
tribe29 / checkmk 1.6.0p18 1.6.0p18.x
checkmk / checkmk 1.6.0-p5 1.6.0-p5.x
checkmk / checkmk 1.6.0-p6 1.6.0-p6.x
checkmk / checkmk 1.6.0-p7 1.6.0-p7.x
checkmk / checkmk 1.6.0-p8 1.6.0-p8.x
checkmk / checkmk 1.6.0-p9 1.6.0-p9.x
checkmk / checkmk 1.6.0-p10 1.6.0-p10.x
checkmk / checkmk 1.6.0-p11 1.6.0-p11.x
checkmk / checkmk 1.6.0-p12 1.6.0-p12.x
checkmk / checkmk 1.6.0-p13 1.6.0-p13.x
checkmk / checkmk 1.6.0-p14 1.6.0-p14.x
checkmk / checkmk 1.6.0-p15 1.6.0-p15.x
checkmk / checkmk 1.6.0-p16 1.6.0-p16.x
checkmk / checkmk 1.6.0 1.6.0.x
checkmk / checkmk 1.6.0-p4 1.6.0-p4.x
checkmk / checkmk 1.6.0-p3 1.6.0-p3.x
checkmk / checkmk 1.6.0-p2 1.6.0-p2.x
checkmk / checkmk 1.6.0-p1 1.6.0-p1.x
checkmk / checkmk 1.6.0-b1 1.6.0-b1.x
checkmk / checkmk 1.6.0-b10 1.6.0-b10.x
checkmk / checkmk 1.6.0-b12 1.6.0-b12.x
checkmk / checkmk 1.6.0-b3 1.6.0-b3.x
checkmk / checkmk 1.6.0-b4 1.6.0-b4.x
checkmk / checkmk 1.6.0-b5 1.6.0-b5.x
checkmk / checkmk 1.6.0-b9 1.6.0-b9.x
checkmk / checkmk 1.6.0-p19 1.6.0-p19.x
checkmk / checkmk 1.6.0-p20 1.6.0-p20.x
checkmk / checkmk 1.6.0-p21 1.6.0-p21.x
checkmk / checkmk 1.6.0-p22 1.6.0-p22.x
checkmk / checkmk 1.6.0-p23 1.6.0-p23.x
checkmk / checkmk 1.6.0-p24 1.6.0-p24.x
checkmk / checkmk 1.6.0-p25 1.6.0-p25.x
checkmk / checkmk 1.5.0 1.6.0