Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40626


An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.


Published

2022-09-14T11:15:53.473

Last Modified

2024-11-21T07:21:44.230

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix zabbix ≤ 6.0.6 Yes
Application zabbix zabbix 6.2.0 Yes
Operating System fedoraproject fedora 37 Yes

References