CVE-2020-15803

MEDIUM

Zabbix < 3.0.31 - XSS

Title source: rule
STIX 2.1

Description

Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

Scores

CVSS v3 6.1
EPSS 0.0507
EPSS Percentile 89.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (11)
debian/debian_linux 9.0
fedoraproject/fedora 31
fedoraproject/fedora 32
opensuse/backports sle-15 sp1 (2 CPE variants)
opensuse/leap 15.1
opensuse/leap 15.2
zabbix/zabbix 3.0.32 rc1
zabbix/zabbix 4.0.22 (2 CPE variants)
zabbix/zabbix 4.4.10 (2 CPE variants)
zabbix/zabbix 5.0.2 (2 CPE variants)
... and 1 more
Published Jul 17, 2020
Tracked Since Feb 18, 2026