An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
| Software | From | Fixed in |
|---|---|---|
| zabbix / zabbix | 5.0.25 | 5.0.25.x |
| zabbix / zabbix | - | 5.0.25 |
| zabbix / zabbix | 5.0.25-rc1 | 5.0.25-rc1.x |