V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-24349
AST
Medium

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has acces…

CVSS
4.4
Medium
EPSS
0.01
p51
Published
2022-01-01
Updated
2022-01-01
Description

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.

Tags · CWE
XSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
Debian_linuxFedora
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: L
Low (L)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.008 · p51
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
zabbixTracked
debian_linux*Tracked
fedora*Tracked
frontend*Tracked
Source databases
AST
DEB
CVE
UBU
Related vulnerabilities