← Vulnerability feed

Vulnerability record · CVE-2017-11507 · published 11 December 2017

CVE-2017-11507: Check mk project check mk cross-site scripting vulnerability

Check Mk Project · Check Mk

A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrary HTML or JavaScript via the output_format parameter, and the username parameter of failed HTTP basic authentication attempts, which is returned unencoded in an internal server error page.

6.1 CVSS 3.0 Medium EPSS 1.0% · top 37.7% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrary HTML or JavaScript via the output_format parameter, and the username parameter of failed HTTP basic authentication attempts, which is returned unencoded in an internal server error page.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11507 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-5340Check mk project check mk code injection vulnerabilityThe wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execu…EPSS 6.1%8.5CVE-2014-2331Check mk project check mk code injection vulnerabilityCheck_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. …EPSS 2.1%6.8CVE-2014-2330Check mk project check mk cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authe…EPSS 1.1%6.1CVE-2017-9781Check mk project check mk cross-site scripting vulnerabilityA cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject…EPSS 1.6%5.5CVE-2014-0243Check mk project check mk link following vulnerabilityCheck_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.EPSS 0.59%5.5CVE-2014-2332Check mk project check mk improper input validation vulnerabilityCheck_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, r…EPSS 1.4%4.9CVE-2014-5339Check mk project check mk vulnerabilityCheck_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations …EPSS 1.8%3.5CVE-2014-2329Check mk project check mk cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject a…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2017-11507), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.