Vulnerabilities
Vulnerable Software
Zabbix:  >> Zabbix  >> 6.0.5  Security Vulnerabilities
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
CVSS Score
8.5
EPSS Score
0.003
Published
2023-07-13
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
CVSS Score
4.8
EPSS Score
0.019
Published
2022-09-14


Contact Us

Shodan ® - All rights reserved