CVE-2023-29454
published 2023-07-13CVE-2023-29454: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.57%
43.8th percentile
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) | zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) |
| zabbix | frontend | 4.0.0 – 4.0.45 | — |
| zabbix | frontend | 5.0.0 – 5.0.33 | — |
| zabbix | frontend | 6.0.0 – 6.0.16 | — |
| zabbix | zabbix | >= 0 < 1:5.0.44+dfsg-1+deb11u1 | 1:5.0.44+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:6.0.23+dfsg-1 | 1:6.0.23+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:6.0.23+dfsg-1 | 1:6.0.23+dfsg-1 |
| zabbix | zabbix | 4.0.0 – 4.0.45 | — |
| zabbix | zabbix | 5.0.0 – 5.0.33 | — |
| zabbix | zabbix | 6.0.0 – 6.0.16 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-29454: zabbix - Stored or persistent cross-site scripting (XSS) is a type of XSS where the attac...
vendor_debian·2023·CVSS 5.4
CVE-2023-29454 [MEDIUM] CVE-2023-29454: zabbix - Stored or persistent cross-site scripting (XSS) is a type of XSS where the attac...
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in 1:6.0.23+dfsg-1)
OSV
CVE-2023-29454: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicati
osv·2023-07-13·CVSS 5.4
CVE-2023-29454 [MEDIUM] CVE-2023-29454: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicati
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
GHSA
GHSA-j6fc-pvcg-2p4f: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicati
ghsa_unreviewed·2023-07-13
CVE-2023-29454 [MEDIUM] CWE-20 GHSA-j6fc-pvcg-2p4f: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicati
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-13
Published