CVE-2010-2790Cross-site Scripting in Zabbix

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 5
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php). NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/zabbix< zabbix 1:1.8.3-1 (bookworm)
Debianzabbix/zabbix< 1:1.8.3-1+3
NVDzabbix/zabbix1.8.2+44

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6f9x-gc6q-v2cg: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class2022-05-17
OSV
CVE-2010-2790: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class2010-08-05

📋Vendor Advisories

1
Debian
CVE-2010-2790: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function ...2010

💬Community

2
Bugzilla
CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326)2010-08-03
Bugzilla
CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326) [fedora-13]2010-08-03