CVE-2022-40626: Reflected XSS in the backurl parameter of Zabbix Frontend
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40626?
CVE-2022-40626 is a vulnerability that allows an unauthenticated user to create a link with reflected JavaScript code in the backurl parameter in Zabbix Frontend.
How does CVE-2022-40626 work?
An unauthenticated user can create a link with reflected JavaScript code in the backurl parameter and send it to other authenticated users, allowing them to create a fake account with predefined login, password, and role.
What software is affected by CVE-2022-40626?
Zabbix versions 6.0.0 to 6.0.6, Zabbix 6.2.0, Fedora 37 are affected by CVE-2022-40626.
What is the severity of CVE-2022-40626?
CVE-2022-40626 has a severity value of 6.1, which is considered medium.
How can I fix CVE-2022-40626?
To fix CVE-2022-40626, update to a version of Zabbix that is not affected by the vulnerability.