[debian-lts-announce] 20230412 [SECURITY] [DLA 3390-1] zabbix security updatemailing list
https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html CVE-2022-35229
LOW
Reflected XSS in discovery page of Zabbix Frontend
Record summary
CVE-2022-35229 has a selected CVSS score of 3.7 (low).
Description
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FrontendBrowse Zabbix / Frontend | CVE List | 4.0.0-4.0.42 | affected |
| 5.0.0-5.0.24 | affected | ||
| 6.0.0-6.0.4 | affected | ||
| 6.2alpha1-6.2beta3 | affected |
References
5[debian-lts-announce] 20230822 [SECURITY] [DLA 3538-1] zabbix security updatemailing list
https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-35229 support.zabbix.com
https://support.zabbix.com/browse/ZBX-21306