{"id":"CVE-2021-40906","details":"CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.","modified":"2026-07-10T04:00:23.902397649Z","published":"2022-03-25T23:15:08.287Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"tribe29:checkmk","cpes":["cpe:2.3:a:tribe29:checkmk:1.6.0b10:*:*:*:*:*:*:*","cpe:2.3:a:tribe29:checkmk:1.6.0b11:*:*:*:*:*:*:*","cpe:2.3:a:tribe29:checkmk:1.6.0p10:*:*:*:*:*:*:*","cpe:2.3:a:tribe29:checkmk:1.6.0p17:*:*:*:*:*:*:*","cpe:2.3:a:tribe29:checkmk:1.6.0p18:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.6.0b10"},{"last_affected":"1.6.0b10"},{"introduced":"1.6.0b11"},{"last_affected":"1.6.0b11"},{"introduced":"1.6.0p10"},{"last_affected":"1.6.0p10"},{"introduced":"1.6.0p17"},{"last_affected":"1.6.0p17"},{"introduced":"1.6.0p18"},{"last_affected":"1.6.0p18"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/Edgarloyola/CVE-2021-40906"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"adf02f46678361844d794effb70eeca27c268548"},{"fixed":"d5ccd5ecc956e665aca80f3c486f7fa46f409424"},{"introduced":"d5ccd5ecc956e665aca80f3c486f7fa46f409424"},{"last_affected":"370fedb12335d97dfdec344e4b15bbb489c72b20"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b9:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p9:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p14:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p15:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p16:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p19:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p20:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p21:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p22:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p23:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p24:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p25:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p8:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.5.0"},{"fixed":"1.6.0"},{"introduced":"1.6.0-NA"},{"last_affected":"1.6.0-NA"},{"introduced":"1.6.0-b1"},{"last_affected":"1.6.0-b1"},{"introduced":"1.6.0-p1"},{"last_affected":"1.6.0-p1"},{"introduced":"1.6.0-b10"},{"last_affected":"1.6.0-b10"},{"introduced":"1.6.0-p10"},{"last_affected":"1.6.0-p10"},{"introduced":"1.6.0-b12"},{"last_affected":"1.6.0-b12"},{"introduced":"1.6.0-p12"},{"last_affected":"1.6.0-p12"},{"introduced":"1.6.0-b3"},{"last_affected":"1.6.0-b3"},{"introduced":"1.6.0-p3"},{"last_affected":"1.6.0-p3"},{"introduced":"1.6.0-b4"},{"last_affected":"1.6.0-b4"},{"introduced":"1.6.0-p4"},{"last_affected":"1.6.0-p4"},{"introduced":"1.6.0-b5"},{"last_affected":"1.6.0-b5"},{"introduced":"1.6.0-p5"},{"last_affected":"1.6.0-p5"},{"introduced":"1.6.0-b9"},{"last_affected":"1.6.0-b9"},{"introduced":"1.6.0-p9"},{"last_affected":"1.6.0-p9"},{"introduced":"1.6.0-p11"},{"last_affected":"1.6.0-p11"},{"introduced":"1.6.0-p13"},{"last_affected":"1.6.0-p13"},{"introduced":"1.6.0-p14"},{"last_affected":"1.6.0-p14"},{"introduced":"1.6.0-p15"},{"last_affected":"1.6.0-p15"},{"introduced":"1.6.0-p16"},{"last_affected":"1.6.0-p16"},{"introduced":"1.6.0-p19"},{"last_affected":"1.6.0-p19"},{"introduced":"1.6.0-p2"},{"last_affected":"1.6.0-p2"},{"introduced":"1.6.0-p20"},{"last_affected":"1.6.0-p20"},{"introduced":"1.6.0-p21"},{"last_affected":"1.6.0-p21"},{"introduced":"1.6.0-p22"},{"last_affected":"1.6.0-p22"},{"introduced":"1.6.0-p23"},{"last_affected":"1.6.0-p23"},{"introduced":"1.6.0-p24"},{"last_affected":"1.6.0-p24"},{"introduced":"1.6.0-p25"},{"last_affected":"1.6.0-p25"},{"introduced":"1.6.0-p6"},{"last_affected":"1.6.0-p6"},{"introduced":"1.6.0-p7"},{"last_affected":"1.6.0-p7"},{"introduced":"1.6.0-p8"},{"last_affected":"1.6.0-p8"}]}}],"versions":["1.6.0-NA","1.6.0-b1","1.6.0-b10","1.6.0-b12","1.6.0-b3","1.6.0-b4","1.6.0-b5","1.6.0-b9","1.6.0-p11","1.6.0-p13","1.6.0-p14","1.6.0-p15","1.6.0-p16","1.6.0-p19","1.6.0-p2","1.6.0-p20","1.6.0-p21","1.6.0-p22","1.6.0-p23","1.6.0-p24","1.6.0-p25","1.6.0-p6","1.6.0-p7","1.6.0-p8","v1.6.0p8","v1.6.0p7","v1.6.0p6","v1.6.0p5","v1.6.0p4","v1.6.0p3","v1.6.0p2","v1.6.0p1","v1.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-40906.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}