Vulnerability Description
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zabbix | Zabbix | <= 3.0.31 |
| Fedoraproject | Fedora | 31 |
| Debian | Debian Linux | 9.0 |
| Opensuse | Backports | sle-15 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00007.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00007.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00018.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://support.zabbix.com/browse/ZBX-18057PatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00007.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00007.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00018.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://support.zabbix.com/browse/ZBX-18057PatchVendor Advisory
FAQ
What is CVE-2020-15803?
CVE-2020-15803 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
How severe is CVE-2020-15803?
CVE-2020-15803 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15803?
Check the references section above for vendor advisories and patch information. Affected products include: Zabbix Zabbix, Fedoraproject Fedora, Debian Debian Linux, Opensuse Backports, Opensuse Leap.