Lucene search

K
cvelistZabbixCVELIST:CVE-2022-35230
HistoryJul 06, 2022 - 11:05 a.m.

CVE-2022-35230 Reflected XSS in graphs page of Zabbix Frontend

2022-07-0611:05:14
CWE-79
Zabbix
www.cve.org
10
cve-2022-35230
zabbix frontend
reflected xss
graphs page
authenticated user
csrf token

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

22.7%

An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

CNA Affected

[
  {
    "vendor": "Zabbix",
    "product": "Frontend",
    "versions": [
      {
        "version": "4.0.0-4.0.42",
        "status": "affected"
      },
      {
        "version": "5.0.0-5.0.24",
        "status": "affected"
      }
    ]
  }
]

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

22.7%