CVE-2022-40626

MEDIUM

Zabbix 6.0.0-6.0.6 - Unauthenticated Reflected Cross-Site Scripting via Backurl Parameter

Title source: llm
STIX 2.1

Description

An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.

References (2)

Core 2
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://support.zabbix.com/browse/ZBX-21350

Scores

CVSS v3 4.8
EPSS 0.0187
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
fedoraproject/fedora 37
zabbix/zabbix 6.2.0
zabbix/zabbix 6.0.0 - 6.0.6
Published Sep 14, 2022
Tracked Since Feb 18, 2026