CVE-2023-29454
MEDIUMZabbix Frontend 4.0.0-4.0.44 - Stored Cross-Site Scripting
Title source: llmDescription
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
References (3)
Core 3
Core References
Vendor Advisory
https://support.zabbix.com/browse/ZBX-22985
Scores
CVSS v3
5.4
EPSS
0.0048
EPSS Percentile
37.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
CWE-79
Status
published
Products (1)
zabbix/frontend
4.0.0 - 4.0.45
Published
Jul 13, 2023
Tracked Since
Feb 18, 2026