Back

MEDIUM

Reflected XSS in discovery page of Zabbix Frontend

Published Jul 6, 2022

Description

An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

Affected products

Remediation

Vendor solution

To remediate this vulnerability, apply the updates

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Zabbix
Published Jul 6, 2022
Updated Nov 3, 2025
Reserved Jul 5, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Zabbix
Published Jul 6, 2022
Updated Nov 3, 2025

GitHub

No data