Zabbix Sia Zabbix是拉脱维亚Zabbix SIA(Zabbix Sia)公司的一套开源的监控系统。该系统支持网络监控、服务器监控、云监控和应用监控等。 Zabbix Sia Zabbix 存在跨站脚本漏洞,该漏洞源于经过身份验证的用户可以使用 XSS 有效负载从配置中创建主机组,其他用户可以使用该主机组。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-23131 | 9.1 CRITICAL | Unsafe client-side session storage leading to authentication bypass/instance takeover via |
| CVE-2022-23134 | 3.7 LOW | Possible view of the setup pages by unauthenticated users if config file already exists |
| CVE-2022-23132 | 3.3 LOW | Incorrect permissions of [/var/run/zabbix] forces dac_override |
No comments yet