CVE-2023-29457: Insufficient validation of Action form input fields
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-29457?
CVE-2023-29457 is a vulnerability in Zabbix Frontend that allows for reflected XSS attacks.
How are reflected XSS attacks carried out?
Reflected XSS attacks occur when a malicious script is reflected off a web application to the victim's browser.
Which software versions are affected by CVE-2023-29457?
Zabbix Frontend versions 4.0.0 to 4.0.45, 5.0.0 to 5.0.34, and 6.0.0 to 6.0.17 are affected.
What is the severity of CVE-2023-29457?
CVE-2023-29457 has a severity rating of 6.1 (medium).
How do I fix CVE-2023-29457?
To fix CVE-2023-29457, upgrade Zabbix Frontend to a version that is not affected (e.g., 4.0.46 or higher, 5.0.35 or higher, 6.0.18 or higher).