CVE-2021-40906 - CVE House
Back to Database
Status published Medium CVE-2021-40906

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not...

Vulnerability Description

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-40906

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

checkmk
Vulnerable Versions:
1.5.0, 1.6.0, 1.6.0b10, 1.6.0b11, 1.6.0p10, 1.6.0p17, 1.6.0p18

Timeline

Official Publish: March 25th, 2022
Last Modified: July 9th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.