MEDIUM
Reflected XSS in discovery page of Zabbix Frontend
Published Jul 6, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.81%
Description
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Affected products
-
Affected
- 4.0.0-4.0.42
- 5.0.0-5.0.24
- 6.0.0-6.0.4
- 6.2alpha1-6.2beta3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
To remediate this vulnerability, apply the updates
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38121 Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html mailing-list
- https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html
- https://support.zabbix.com/browse/ZBX-21306 Issue TrackingPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38121 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html | mailing-list | |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html | mailing-list | |
| https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html | ||
| https://support.zabbix.com/browse/ZBX-21306 | Issue TrackingPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Jul 6, 2022
Updated Nov 3, 2025
Reserved Jul 5, 2022
Link CVE-2022-35229
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data