Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc8w-x6qp-w4p7

Опубликовано: 02 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.5

Описание

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

EPSS

Процентиль: 31%
0.00114
Низкий

7.5 High

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
5 месяцев назад

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

nvd
5 месяцев назад

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

debian
5 месяцев назад

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross- ...

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость веб-интейрфеса универсальной системы мониторинга Zabbix, позволяющая нарушителю провести атаку межсайтового скриптинга

CVSS3: 7.5
redos
3 месяца назад

Уязвимость zabbix-server-pgsql

EPSS

Процентиль: 31%
0.00114
Низкий

7.5 High

CVSS4

Дефекты

CWE-79