PT-2022-6481 · Zabbix+5 · Zabbix+5

Internal Research

+1

·

Published

2021-08-20

·

Updated

2024-12-10

·

CVE-2022-35230

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The issue is related to the lack of protection of the web page structure in Zabbix, allowing an authenticated user to create a link with reflected Javascript code for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2582
ALT-PU-2021-2668
ALT-PU-2023-6268
BDU:2023-01712
CVE-2022-35230
DLA-3390-1
DLA-3909-1
OPENSUSE-SU-2024:12212-1
ROSA-SA-2024-2539
SUSE-SU-2022:3101-1
SUSE-SU-2022_3101-1
USN-6751-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Zabbix