CVE-2022-35230
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
06/07/2022
Last modified:
03/11/2025
Description
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Impact
Base Score 3.x
3.70
Severity 3.x
LOW
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 5.0.25 (excluding) | |
| cpe:2.3:a:zabbix:zabbix:5.0.25:-:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:5.0.25:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



