CVE-2023-32721: Stored XSS in Maps element
Published Oct 12, 2023
·Updated
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
Affected Software
7 affected components
Zabbix Zabbix>=4.0.0<=4.0.47
Zabbix Zabbix>=5.0.0<=5.0.36
Zabbix Zabbix>=6.0.0<=6.0.20
Zabbix Zabbix>=6.4.0<=6.4.5
Zabbix Zabbix=7.0.0-alpha1
Zabbix Zabbix=7.0.0-alpha2
Zabbix Zabbix=7.0.0-alpha3
Event History
Oct 12, 2023
CVE Published
via MITRE·06:04 AM
Data Sourced
via MITRE·06:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-32721?
CVE-2023-32721 is a stored XSS vulnerability found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
2
How severe is CVE-2023-32721?
CVE-2023-32721 has a severity rating of 5.4 (high).
3
What software is affected by CVE-2023-32721?
Zabbix versions between 4.0.0 and 4.0.47, 5.0.0 and 5.0.36, 6.0.0 and 6.0.20, 6.4.0 and 6.4.5, as well as 7.0.0-alpha1, 7.0.0-alpha2, and 7.0.0-alpha3 are affected by CVE-2023-32721.
4
How can I fix CVE-2023-32721?
To fix CVE-2023-32721, it is recommended to upgrade to a patched version of Zabbix.
5
Where can I find more information about CVE-2023-32721?
More information about CVE-2023-32721 can be found at the following reference link: https://support.zabbix.com/browse/ZBX-23389