CRITICAL · 9.6

CVE-2023-32725

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particula...

Vulnerability Description

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

CVSS Score

9.6

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZabbixZabbix Server>= 6.0.0, <= 6.0.21
ZabbixFrontend>= 6.0.0, <= 6.0.21

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-32725?

CVE-2023-32725 is a vulnerability with a CVSS score of 9.6 (CRITICAL). The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particula...

How severe is CVE-2023-32725?

CVE-2023-32725 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-32725?

Check the references section above for vendor advisories and patch information. Affected products include: Zabbix Zabbix Server, Zabbix Frontend.