CVE-2022-35229: Reflected XSS in discovery page of Zabbix Frontend
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-35229?
CVE-2022-35229 is a vulnerability that allows an authenticated user to create a link with reflected Javascript code for the discovery page and send it to other users.
How can an attacker exploit CVE-2022-35229?
An attacker can exploit CVE-2022-35229 by creating a malicious link with reflected Javascript code and tricking other users into clicking on it.
What is the severity of CVE-2022-35229?
CVE-2022-35229 has a severity rating of medium with a CVSS score of 5.4.
Which software versions are affected by CVE-2022-35229?
Zabbix versions 4.0.0 up to exclusive, 5.0.0 up to inclusive (up to version 5.0.25), and 6.0.0 up to inclusive (up to version 6.0.4) are affected by CVE-2022-35229.
Are there any fixes for CVE-2022-35229?
Yes, fixes for CVE-2022-35229 are available. Please refer to the provided references for more information.