A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
2024-11-28T08:15:05.290
2025-10-08T15:31:30.720
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zabbix | zabbix | < 6.0.32 | Yes |
| Application | zabbix | zabbix | < 6.4.17 | Yes |
| Application | zabbix | zabbix | 7.0.0 | Yes |