ZeroHour

CVE-2023-32725

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

Vendors
zabbix
Products
zabbix server, frontend
Weakness
CWE-565
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.