Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2020-15803

Severity
6.1MEDIUM
EPSS
2.3%
top 15.25%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 17
Latest updateJun 15

Description

Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Debianzabbix< 1:5.0.2+dfsg-1+3
NVDzabbix/zabbix4.0.04.0.21+7
NVDopensuse/leap15.1, 15.2+1
NVDopensuse/backportssle-15

Also affects: Debian Linux 9.0, Fedora 31, 32

Patches

🔴Vulnerability Details

3
GHSA
GHSA-79cm-2gxq-7x9r: Zabbix before 32022-05-24
CVEList
CVE-2020-15803: Zabbix before 32020-07-17
OSV
CVE-2020-15803: Zabbix before 32020-07-17

💥Exploits & PoCs

1
Exploit-DB
Zabbix 5.0.0 - Stored XSS via URL Widget Iframe2020-12-04

📋Vendor Advisories

2
Ubuntu
Zabbix vulnerabilities2022-06-15
Debian
CVE-2020-15803: zabbix - Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10...2020

💬Community

2
Bugzilla
CVE-2020-15803 zabbix: stored XSS in the URL Widget2020-07-17
Bugzilla
CVE-2020-15803 zabbix: stored XSS in the URL Widget [fedora-all]2020-07-17
CVE-2020-15803 (MEDIUM CVSS 6.1) | Zabbix before 3.0.32rc1 | cvebase.io