[debian-lts-announce] 20230412 [SECURITY] [DLA 3390-1] zabbix security updatemailing list
https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html CVE-2022-35230
LOW
Reflected XSS in graphs page of Zabbix Frontend
Record summary
CVE-2022-35230 has a selected CVSS score of 3.7 (low).
Description
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FrontendBrowse Zabbix / Frontend | CVE List | 4.0.0-4.0.42 | affected |
| 5.0.0-5.0.24 | affected |
References
4lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-35230 support.zabbix.com
https://support.zabbix.com/browse/ZBX-21305