CVE-2020-15803: XSS
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15803?
CVE-2020-15803 is a vulnerability that allows stored XSS in the URL Widget in Zabbix before version 3.0.32rc1, 4.x before version 4.0.22rc1, 4.1.x through 4.4.x before version 4.4.10rc1, and 5.x before version 5.0.2rc1.
How severe is CVE-2020-15803?
CVE-2020-15803 has a severity rating of 6.1 (medium).
How does CVE-2020-15803 affect Zabbix?
CVE-2020-15803 affects Zabbix versions before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1.
What is the Common Weakness Enumeration (CWE) for CVE-2020-15803?
The Common Weakness Enumeration (CWE) for CVE-2020-15803 is CWE-79.
Where can I find more information about CVE-2020-15803?
You can find more information about CVE-2020-15803 in the following references: [1] http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00007.html [2] https://lists.debian.org/debian-lts-announce/2020/08/msg00007.html [3] https://lists.debian.org/debian-lts-announce/2021/04/msg00018.html