PT-2025-14462 · Zabbix+3 · Zabbix+3

Published

2025-04-01

·

Updated

2025-10-08

·

CVE-2024-45699

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The endpoint "/zabbix.php?action=export.valuemaps" suffers from a Cross-Site Scripting issue via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding, allowing a JavaScript payload to be injected into the endpoint and executed within the context of the victim's browser.
Recommendations As a temporary workaround, consider restricting access to the "/zabbix.php?action=export.valuemaps" endpoint until a patch is available. Avoid using the backurl parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5871
ALT-PU-2025-5998
BDU:2025-05634
CVE-2024-45699
DLA-4131-1

Affected Products

Alt Linux
Debian
Red Os
Zabbix