Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32725


The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.


Published

2023-12-18T10:15:06.550

Last Modified

2024-11-21T08:03:55.217

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-565
  • Type: Primary
    CWE-565

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix zabbix_server ≤ 6.0.21 Yes
Application zabbix zabbix_server ≤ 6.4.6 Yes
Application zabbix zabbix_server 7.0.0 Yes
Application zabbix zabbix_server 7.0.0 Yes
Application zabbix zabbix_server 7.0.0 Yes
Application zabbix frontend ≤ 6.0.21 Yes
Application zabbix frontend ≤ 6.4.6 Yes
Application zabbix frontend 7.0.0 Yes
Application zabbix frontend 7.0.0 Yes
Application zabbix frontend 7.0.0 Yes

References