Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-45699

Опубликовано: 02 апр. 2025
Источник: nvd
EPSS Низкий

Описание

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

EPSS

Процентиль: 12%
0.00043
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
5 месяцев назад

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

debian
5 месяцев назад

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross- ...

github
5 месяцев назад

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость веб-интейрфеса универсальной системы мониторинга Zabbix, позволяющая нарушителю провести атаку межсайтового скриптинга

CVSS3: 7.5
redos
3 месяца назад

Уязвимость zabbix-server-pgsql

EPSS

Процентиль: 12%
0.00043
Низкий

Дефекты

CWE-79