An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zabbix | Apr 14, 2023 | Jul 6, 2022 |
| Ubuntu | — | Upgrade zabbix-proxy-pgsql (Ubuntu Pro)Upgrade zabbix-server-mysql (Ubuntu Pro)Upgrade zabbix-proxy-mysql (Ubuntu Pro)Upgrade zabbix-agent (Ubuntu Pro)Upgrade zabbix-java-gateway (Ubuntu Pro)Upgrade zabbix-proxy-sqlite3 (Ubuntu Pro)Upgrade zabbix-frontend-php (Ubuntu Pro)Upgrade zabbix-server-pgsql (Ubuntu Pro) | Apr 26, 2024 | Jul 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub