CVE-2022-35229
06.07.2022, 11:15
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 𝑥 < 4.0.0 |
| zabbix | zabbix | 5.0.0 ≤ 𝑥 < 5.0.25 |
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.4 |
| zabbix | zabbix | 5.0.25 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| zabbix |
|
References