CVE-2022-35230: Reflected XSS in graphs page of Zabbix Frontend
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-35230?
CVE-2022-35230 is a vulnerability in Zabbix that allows an authenticated user to create a link with reflected Javascript code and send it to other users.
Which software versions are affected by CVE-2022-35230?
Zabbix versions 5.0.25 and 5.0.25-rc1 are affected by CVE-2022-35230.
How can an authenticated user exploit CVE-2022-35230?
An authenticated user can create a link with reflected Javascript code for the graphs page and send it to other users.
What is the severity of CVE-2022-35230?
CVE-2022-35230 has a severity value of 5.4, which is considered medium.
Is there a fix available for CVE-2022-35230?
Yes, a fix for CVE-2022-35230 is available. Please refer to the provided references for more information.