PT-2022-4909 · Zabbix+2 · Zabbix Frontend+3

Alexander Vladishev

+1

·

Published

2022-07-08

·

Updated

2022-09-30

·

CVE-2022-40626

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zabbix Frontend (affected versions not specified)
Description The issue is related to the lack of protection measures for the web page structure when handling the backurl parameter in Zabbix Frontend. This can be exploited by an unauthenticated user to create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users. The goal is to create a fake account with predefined login, password, and role. The exploitation can lead to cross-site scripting attacks using a specially crafted malicious link.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2302
BDU:2022-06077
CVE-2022-40626

Affected Products

Alt Linux
Astra Linux
Zabbix
Zabbix Frontend