PT-2022-4509 · Zabbix+2 · Zabbix Frontend+3

Alexander Vladishev

+1

·

Published

2022-03-09

·

Updated

2024-10-03

·

CVE-2022-24919

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zabbix Frontend (affected versions not specified)
Description The issue allows an authenticated user to create a link with reflected Javascript code inside it for the graphs' page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-05377
CVE-2022-24919
DLA-2980-1
DLA-3390-1
DLA-3909-1
SUSE-SU-2022:1254-1

Affected Products

Astra Linux
Suse
Zabbix
Zabbix Frontend