CVE-2022-35229
Summary
| CVE | CVE-2022-35229 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-06 11:15:00 UTC |
| Updated | 2023-08-22 19:16:00 UTC |
| Description | An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3538-1] zabbix security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 3390-1] zabbix security update | MLIST | lists.debian.org | |
| [ZBX-21306] Reflected XSS in discovery page of Zabbix Frontend [CVE-2022-35229] - ZABBIX SUPPORT | CONFIRM | support.zabbix.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: internal research