Vulnerabilities
Vulnerable Software
Zabbix:  >> Zabbix  >> 6.4.19  Security Vulnerabilities
The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-04-02
The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or the attacker to know the community/auth details. The attack requires an SNMP item to be configured as text on the target host.
CVSS Score
3.7
EPSS Score
0.002
Published
2024-11-27


Contact Us

Shodan ® - All rights reserved