CVE-2023-29452: Remove possibility to add html into Geomap attribution field
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29452?
CVE-2023-29452 is a vulnerability in the Zabbix software that allows the use of HTML in the "Attribution text" field when the "Other" Tile provider is selected.
How does CVE-2023-29452 affect Zabbix?
CVE-2023-29452 affects Zabbix versions between 6.0.0 and 6.0.17, as well as version 6.4.0 and its release candidates.
What is the severity of CVE-2023-29452?
CVE-2023-29452 has a severity score of 5.4, which is considered medium.
How can I fix CVE-2023-29452?
To fix CVE-2023-29452, it is recommended to update Zabbix to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2023-29452?
You can find more information about CVE-2023-29452 on the Zabbix support page: [link](https://support.zabbix.com/browse/ZBX-22981).