Vulnerability Database

319,896

Total vulnerabilities in the database

CVE-2023-32725

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

  • Published: Dec 18, 2023
  • Updated: Nov 16, 2025
  • CVE: CVE-2023-32725
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.6
  • AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CWEs:

Software From Fixed in
zabbix / zabbix_server 7.0.0-alpha1 7.0.0-alpha1.x
zabbix / zabbix_server 7.0.0-alpha2 7.0.0-alpha2.x
zabbix / zabbix_server 7.0.0-alpha3 7.0.0-alpha3.x
zabbix / zabbix_server 6.4.0 6.4.6.x
zabbix / zabbix_server 6.0.0 6.0.21.x
zabbix / frontend 7.0.0-alpha3 7.0.0-alpha3.x
zabbix / frontend 7.0.0-alpha2 7.0.0-alpha2.x
zabbix / frontend 7.0.0-alpha1 7.0.0-alpha1.x
zabbix / frontend 6.4.0 6.4.6.x
zabbix / frontend 6.0.0 6.0.21.x