After the initial setup process, some steps of setup.php file are reachable not only by super-administrators but also by unauthenticated users. A malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
id: CVE-2022-23134
info:
name: Zabbix Setup Configuration Authentication Bypass
author: bananab
...