CRITICAL🇵🇱 Wersja polska

CVE-2023-32725

CVSS 9.6v3.1pub. 2023-12-18upd. 2024-11-21

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

🤖 AI Analysis
How it works

When a user tests a URL widget or the system executes a scheduled report, the Zabbix server sends an HTTP request to the configured URL, including the logged-in user's session cookie. The owner or controller of the target website can intercept this cookie. The session cookie obtained in this way can then be used to authenticate to the Zabbix frontend interface as that user, without knowing their password.

Impact

An attacker who intercepts a session cookie can gain full access to the Zabbix interface with the compromised user's permissions, which depending on the role may result in takeover of the monitored infrastructure, modification of configuration, or disclosure of sensitive environmental data.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (https://support.zabbix.com/browse/ZBX-23854). Additionally, it is recommended to review the configuration of URL widgets and scheduled reports to verify that they point only to trusted, internal addresses.

Who is affected

Zabbix Server and Zabbix Frontend — versions indicated in the vendor's references (https://support.zabbix.com/browse/ZBX-23854)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Zabbix Frontend

    APP
    Zabbix
    7.0.06.0.0 – 6.0.216.4.0 – 6.4.6
  • Zabbix Server

    APP
    Zabbix
    7.0.06.0.0 – 6.0.216.4.0 – 6.4.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-27232MEDIUM6.8same product

Uwierzytelniony Zabbix Super Admin może wykorzystać akcję oauth.authorize do odczytania dowolnych plików z ser...

CVE-2025-49643MEDIUM6.0same product

Uwierzytelniony użytkownik Zabbix (w tym użytkownik Guest) może spowodować nieproporcjonalne obciążenie CPU se...

CVE-2023-32727MEDIUM6.8same product

An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malici...

CVE-2023-30958MEDIUM4.7same product

A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks...

CVE-2023-29455MEDIUM5.4same product

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a ...