DescriptionCheckmk versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3 contain a stored cross-site scripting vulnerability in dashboard dashlet title links due to insufficient sanitization that allows attackers with dashboard creation privileges to inject malicious scripts. Attackers can craft dashlet title links containing XSS payloads that execute in victims' browsers when they click the link on a shared dashboard, potentially stealing session tokens or performing unauthorized actions.