CVE-2023-29454Improper Input Validation in Zabbix

Severity
5.4MEDIUMNVD
EPSS
0.8%
top 25.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13

Description

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

Debianzabbix/zabbix< 1:5.0.44+dfsg-1+deb11u1+2
CVEListV5zabbix/zabbix4.0.04.0.45+2
NVDzabbix/frontend4.0.04.0.45+2

🔴Vulnerability Details

3
CVEList
Persistent XSS in the user form2023-07-13
OSV
CVE-2023-29454: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicati2023-07-13
GHSA
GHSA-j6fc-pvcg-2p4f: Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicati2023-07-13

📋Vendor Advisories

1
Debian
CVE-2023-29454: zabbix - Stored or persistent cross-site scripting (XSS) is a type of XSS where the attac...2023
CVE-2023-29454 — Improper Input Validation in Zabbix | cvebase