CVE-2023-29450

HIGH

Zabbix < 5.0.33 - Unauthorized File System Access via JavaScript Pre-processing

Title source: llm
STIX 2.1

Description

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

Scores

CVSS v3 8.5
EPSS 0.0105
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-552 CWE-200
Status published
Products (1)
zabbix/zabbix < 5.0.33
Published Jul 13, 2023
Tracked Since Feb 18, 2026