CVE-2022-40626Cross-site Scripting in Zabbix

Severity
6.1MEDIUMNVD
CNA4.8
EPSS
1.9%
top 16.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateSep 15

Description

An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

CVEListV5zabbix/frontend6.0.0-6.0.6, 6.2.0+1
Debianzabbix/zabbix< 1:6.0.7+dfsg-2+2
NVDzabbix/zabbix6.0.06.0.6+1

Also affects: Fedora 37

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3g95-xf53-275x: An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in orde2022-09-15
CVEList
Reflected XSS in the backurl parameter of Zabbix Frontend2022-09-14
OSV
CVE-2022-40626: An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in orde2022-09-14

📋Vendor Advisories

1
Debian
CVE-2022-40626: zabbix - An unauthenticated user can create a link with reflected Javascript code inside ...2022
CVE-2022-40626 — Cross-site Scripting in Zabbix | cvebase