cbcvebase.
CVE-2020-15803
published 2020-07-17

CVE-2020-15803: Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

PriorityP351medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
32.30%
98.1th percentile
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianzabbix< zabbix 1:5.0.2+dfsg-1 (bookworm)zabbix 1:5.0.2+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensusebackports
opensuseleap
opensuseleap
zabbixzabbix<= 3.0.31
zabbixzabbix
zabbixzabbix
zabbixzabbix
zabbixzabbix
zabbixzabbix>= 0 < 1:5.0.2+dfsg-11:5.0.2+dfsg-1
zabbixzabbix>= 0 < 1:5.0.2+dfsg-11:5.0.2+dfsg-1
zabbixzabbix>= 0 < 1:5.0.2+dfsg-11:5.0.2+dfsg-1
zabbixzabbix>= 0 < 1:5.0.2+dfsg-11:5.0.2+dfsg-1
zabbixzabbix>= 0 < 1:2.2.2+dfsg-1ubuntu1+esm41:2.2.2+dfsg-1ubuntu1+esm4
zabbixzabbix>= 0 < 1:2.4.7+dfsg-2ubuntu2.1+esm31:2.4.7+dfsg-2ubuntu2.1+esm3
zabbixzabbix>= 0 < 1:3.0.12+dfsg-1ubuntu0.1~esm31:3.0.12+dfsg-1ubuntu0.1~esm3
zabbixzabbix>= 0 < 1:4.0.17+dfsg-1ubuntu0.1~esm11:4.0.17+dfsg-1ubuntu0.1~esm1
zabbixzabbix4.0.0 – 4.0.21
zabbixzabbix4.4 – 4.4.9
zabbixzabbix5.0.0 – 5.0.1

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.