CVE-2022-40626
14.09.2022, 11:15
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.6 |
| zabbix | zabbix | 6.2.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References