Vulnerabilities
Vulnerable Software
Zabbix:  >> Zabbix  >> 4.0.17  Security Vulnerabilities
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
CVSS Score
9.1
EPSS Score
0.937
Published
2019-10-09
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.
CVSS Score
5.3
EPSS Score
0.004
Published
2019-08-17


Contact Us

Shodan ® - All rights reserved