CVE-2022-40626
14.09.2022, 11:15
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
Vendor | Product | Version |
---|---|---|
zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.6 |
zabbix | zabbix | 6.2.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References