MEDIUM · 4.6

CVE-2022-24349

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can...

Vulnerability Description

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ZabbixFrontend>= 4.0.0, <= 4.0.38
DebianDebian Linux9.0
FedoraprojectFedora34

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-24349?

CVE-2022-24349 is a vulnerability with a CVSS score of 4.6 (MEDIUM). An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can...

How severe is CVE-2022-24349?

CVE-2022-24349 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-24349?

Check the references section above for vendor advisories and patch information. Affected products include: Zabbix Frontend, Debian Debian Linux, Fedoraproject Fedora.