Insufficient Escaping Vulnerability in Checkmk Reporting Tool
CVE-2025-39664
7.1HIGH
What is CVE-2025-39664?
The Checkmk reporting tool contains a vulnerability due to insufficient escaping in the report scheduler. This flaw allows authenticated attackers to manipulate the storage location of report file pairs, potentially leading them to store files outside the designated root directory, which can compromise data security and integrity.
Affected Version(s)
Checkmk 2.4.0 < 2.4.0p13
Checkmk 2.3.0 < 2.3.0p38
Checkmk 2.2.0 < 2.2.0p46