![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2022-35229 |
Description: | An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. |
Test IDs: | 1.3.6.1.4.1.25623.1.1.1.2.2023.3538 1.3.6.1.4.1.25623.1.1.1.2.2023.3390 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2022-35229 https://support.zabbix.com/browse/ZBX-21306 https://support.zabbix.com/browse/ZBX-21306 https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html |