CVE-2022-23133
published 2022-01-13CVE-2022-23133: An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.03%
60.0th percentile
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:6.0.7+dfsg-2 (bookworm) | zabbix 1:6.0.7+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| zabbix | frontend | — | — |
| zabbix | frontend | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:5.0.44+dfsg-1+deb11u1 | 1:5.0.44+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:6.0.7+dfsg-2 | 1:6.0.7+dfsg-2 |
| zabbix | zabbix | >= 0 < 1:6.0.7+dfsg-2 | 1:6.0.7+dfsg-2 |
| zabbix | zabbix | >= 0 < 1:6.0.7+dfsg-2 | 1:6.0.7+dfsg-2 |
| zabbix | zabbix | 5.0.0 – 5.0.18 | — |
| zabbix | zabbix | 5.4.0 – 5.4.8 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-23133: zabbix - An authenticated user can create a hosts group from the configuration with XSS p...
vendor_debian·2022·CVSS 6.3
CVE-2022-23133 [MEDIUM] CVE-2022-23133: zabbix - An authenticated user can create a hosts group from the configuration with XSS p...
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.
Scope: local
bookworm: resolved (fixed in 1:6.0.7+dfsg-2)
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.7+dfsg-2)
sid: resolved (fixed in 1:6.0.7+dfsg-2)
trixie: resolved (fixed in 1:6.0.7+dfsg-2)
GHSA
GHSA-2r84-x97c-3ch4: An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users
ghsa_unreviewed·2022-01-14
CVE-2022-23133 [MEDIUM] CWE-79 GHSA-2r84-x97c-3ch4: An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.
OSV
CVE-2022-23133: An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users
osv·2022-01-13·CVSS 5.4
CVE-2022-23133 [MEDIUM] CVE-2022-23133: An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/https://support.zabbix.com/browse/ZBX-20388https://lists.debian.org/debian-lts-announce/2024/10/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/https://support.zabbix.com/browse/ZBX-20388
2022-01-13
Published