Zabbix

Zabbix

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 13.07.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:57:04

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.

  • EPSS 64.06%
  • Veröffentlicht 13.07.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:57:05

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.

  • EPSS 0.76%
  • Veröffentlicht 13.07.2023 10:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:07

Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we...

  • EPSS 1.16%
  • Veröffentlicht 13.07.2023 09:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:06

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Admin...

  • EPSS 1.26%
  • Veröffentlicht 13.07.2023 09:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:06

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 05.12.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:26:41

A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)

  • EPSS 0.72%
  • Veröffentlicht 14.09.2022 11:15:53
  • Zuletzt bearbeitet 21.11.2024 07:21:44

An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.

  • EPSS 0.72%
  • Veröffentlicht 06.07.2022 11:15:09
  • Zuletzt bearbeitet 03.11.2025 22:15:59

An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is diffic...

  • EPSS 0.73%
  • Veröffentlicht 06.07.2022 11:15:08
  • Zuletzt bearbeitet 03.11.2025 22:15:58

An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is dif...

Exploit
  • EPSS 4.04%
  • Veröffentlicht 27.01.2022 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:33:37

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.