Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qjqp-r6hf-xpqh

Опубликовано: 06 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

EPSS

Процентиль: 21%
0.00285
Низкий

7.3 High

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

nvd
3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

debian
3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in ...

CVSS3: 8.4
fstec
3 месяца назад

Уязвимость пользовательского интерфейса универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 8.4
redos
26 дней назад

Уязвимость zabbix7.4

EPSS

Процентиль: 21%
0.00285
Низкий

7.3 High

CVSS4

Дефекты

CWE-79