CVE-2022-40626
14.09.2022, 11:15
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.6 |
| zabbix | zabbix | 6.2.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zabbix | frontend | 6.2.0 | CNA |
Debian Releases
Ubuntu Releases
References