Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30063
HistoryApr 21, 2021 - 5:55 a.m.

Cross-Site Request Forgery (CSRF)

2021-04-2105:55:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

30.9%

zabbix is vulnerable to cross-site request forgery (CSRF). Lack of CSRF protection mechanism in the CControllerAuthenticationUpdate controller allows an attacker to submit requests on behalf of the authenticated Zabbix user.