An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
2022-09-14T11:15:53.473
2024-11-21T07:21:44.230
Modified
CVSSv3.1: 4.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zabbix | zabbix | ≤ 6.0.6 | Yes |
Application | zabbix | zabbix | 6.2.0 | Yes |
Operating System | fedoraproject | fedora | 37 | Yes |