Stored cross-site scripting in Zabbix - CVE-2022-23133
Published: February 23, 2022
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when processing host groups. A remote user can permanently inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Fedora
zabbix40
zabbix50
zabbix
How to mitigate CVE-2022-23133
zabbix40 - update to 4.0.37-1.el7
zabbix50 - update to 5.0.19-1.el7
zabbix - addressed in versions 5.0.19-1.fc34, 5.0.19-1.fc35, 5.0-820220117005358.9edba152
External References
- https://support.zabbix.com/browse/ZBX-20388
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/