CVE-2022-23134

Possible view of the setup pages by unauthenticated users if config file already exists

Basic Information

CVE State
PUBLISHED
Reserved Date
January 11, 2022
Published Date
January 13, 2022
Last Updated
January 29, 2025
Vendor
Zabbix
Product
Frontend
Description
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVSS Scores

CVSS v3.1

3.7 - LOW

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

SSVC Information

Exploitation
active
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2022-02-22 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-02-22 00:00:00 UTC

Scanner Integrations