SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23133

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users.

MEDIUM 5.4EPSS 1.03%

Does this matter?

Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.

Description

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zabbix/zabbix · fedoraproject/fedora
Source
security@zabbix.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.