Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv97-qj5h-25f3

Опубликовано: 09 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

EPSS

Процентиль: 100%
0.93119
Критический

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-287
CWE-863

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 4 лет назад

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVSS3: 3.7
nvd
около 4 лет назад

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVSS3: 3.7
debian
около 4 лет назад

After the initial setup process, some steps of setup.php file are reac ...

CVSS3: 5.3
fstec
около 4 лет назад

Уязвимость конфигурации setup.php универсальной системы мониторинга Zabbix , связанная с ошибками авторизации, позволяющая нарушителю изменить параметры конфигурации

suse-cvrf
почти 4 года назад

Security update for zabbix

EPSS

Процентиль: 100%
0.93119
Критический

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-287
CWE-863