An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
| Software | From | Fixed in |
|---|---|---|
| zabbix / zabbix | 5.0.25 | 5.0.25.x |
| zabbix / zabbix | 6.0.0 | 6.0.4.x |
| zabbix / zabbix | 5.0.0 | 5.0.25 |
| zabbix / zabbix | - | 4.0.0 |