cbcvebase.
CVE-2022-23133
published 2022-01-13

CVE-2022-23133: An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an…

PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.03%
60.0th percentile
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianzabbix< zabbix 1:6.0.7+dfsg-2 (bookworm)zabbix 1:6.0.7+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
zabbixfrontend
zabbixfrontend
zabbixzabbix
zabbixzabbix>= 0 < 1:5.0.44+dfsg-1+deb11u11:5.0.44+dfsg-1+deb11u1
zabbixzabbix>= 0 < 1:6.0.7+dfsg-21:6.0.7+dfsg-2
zabbixzabbix>= 0 < 1:6.0.7+dfsg-21:6.0.7+dfsg-2
zabbixzabbix>= 0 < 1:6.0.7+dfsg-21:6.0.7+dfsg-2
zabbixzabbix5.0.0 – 5.0.18
zabbixzabbix5.4.0 – 5.4.8

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.