6 Medium
AI Score
Confidence
Low
0.003 Low
EPSS
Percentile
71.1%
Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.
www.zabbix.com/rn1.8.6.php
exchange.xforce.ibmcloud.com/vulnerabilities/69377
support.zabbix.com/browse/ZBX-3840