Total vulnerabilities in the database
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Software | From | Fixed in |
---|---|---|
zabbix / zabbix | 5.0.25 | 5.0.25.x |
zabbix / zabbix | 6.0.0 | 6.0.4.x |
zabbix / zabbix | 5.0.0 | 5.0.25 |
zabbix / zabbix | - | 4.0.0 |