← Back

CVE-2022-24349

nvd nist
Published: Mar 9, 2022Modified: Jun 17, 2026

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.3 / Impact: 2.7
Source: NVD

Description

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.

Affected (7)

1 product
Frontend
1 product
Debian Linux
1 product
Fedora
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 4.0.0 to 4.0.38
From 5.0.0 to 5.0.20
From 5.4.0 to 5.4.10
Version 6.0.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Fedoraproject
Version 34
Version 35

References (13)

Source: security@zabbix.com
Third Party Advisory
Source: security@zabbix.com
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.