Reflected XSS in discovery page of Zabbix Frontend
Vulnerability Description
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-35229
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- internal research
References
More from Zabbix
View All →Affected Vendor
Zabbix
View all reports →