Information disclosure in Zabbix - CVE-2017-2826
Published: April 16, 2018 / Updated: November 9, 2020
Zabbix
Detailed vulnerability description
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information on the target system.
The weakness exists in the iConfig proxy request feature due to improper handling of iConfig proxy requests. A remote attacker can submit customized iConfig proxy request packets and gain access to potentially sensitive information.