CVE-2016-10742

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
17/02/2019
Last modified:
21/11/2020

Description

Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 2.2.20 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.12 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 3.1.0 (including) 3.2.9 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 3.3.0 (including) 3.4.3 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*