CVE-2023-29455: Reflected XSS in several fields of graph form
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2023-29455.
What is a reflected XSS attack?
A reflected XSS attack, also known as a non-persistent attack, occurs when a malicious script is reflected off a web application to the victim's browser.
How does a reflected XSS attack work?
A reflected XSS attack works by sending a request to a vulnerable website, which then reflects a malicious script onto the victim's browser.
What software is affected by this XSS vulnerability?
The Zabbix Frontend software versions 4.0.0 to 4.0.45 and 5.0.0 to 5.0.33 are affected by this XSS vulnerability.
What is the severity of CVE-2023-29455?
The severity of CVE-2023-29455 is medium, with a CVSS score of 6.1.
How can I fix this XSS vulnerability?
To fix this XSS vulnerability, it is recommended to update the Zabbix Frontend software to a version that is not affected by the vulnerability. Refer to the vendor's website or security advisory for detailed instructions.