CVE-2023-32725

CRITICAL

URL Widget - Auth Bypass

Title source: llm
STIX 2.1

Description

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

Scores

CVSS v3 9.6
EPSS 0.0027
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-565
Status published
Products (4)
zabbix/frontend 7.0.0 alpha1 (3 CPE variants)
zabbix/frontend 6.0.0 - 6.0.21
zabbix/zabbix_server 7.0.0 alpha1 (3 CPE variants)
zabbix/zabbix_server 6.0.0 - 6.0.21
Published Dec 18, 2023
Tracked Since Feb 18, 2026