Lucene search

K
cvelistZabbixCVELIST:CVE-2024-22119
HistoryFeb 09, 2024 - 8:26 a.m.

CVE-2024-22119 Stored XSS in graph items select form

2024-02-0908:26:20
CWE-20
Zabbix
www.cve.org
vulnerability
validation
input field
graph page
items section
stored xss
cve-2024-22119

5.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Frontend"
    ],
    "product": "Zabbix",
    "repo": "https://git.zabbix.com/",
    "vendor": "Zabbix",
    "versions": [
      {
        "changes": [
          {
            "at": "5.0.40rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "5.0.39 ",
        "status": "affected",
        "version": "5.0.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "6.0.24rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.0.23",
        "status": "affected",
        "version": "6.0.0 ",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "6.4.9rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.4.8",
        "status": "affected",
        "version": "6.4.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "7.0.0alpha8",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "7.0.0alpha7",
        "status": "affected",
        "version": "7.0.0alpha1",
        "versionType": "git"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%