CVE-2022-24349
CVE-2022-24349 is a medium-severity vulnerability in Zabbix Frontend with a CVSS 3.x base score of 4.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-79.
Key facts
- Severity: Medium (CVSS 3.x base score 4.6)
- CVSS v2: 2.1
- EPSS exploit prediction: 1% (68th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-79
- Affected product: Zabbix Frontend
- Published:
- Last modified:
Description
An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.
Frequently asked questions
- What is CVE-2022-24349?
- An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.
- How severe is CVE-2022-24349?
- CVE-2022-24349 has a CVSS 3.x base score of 4.6, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2022-24349 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (68th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-24349?
- CVE-2022-24349 primarily affects Zabbix Frontend. In total, 5 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-24349?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2022-24349 published?
- CVE-2022-24349 was published on 2022-03-09 and last updated on 2026-06-17.
References
- https://lists.debian.org/debian-lts-announce/2022/04/msg00011.html
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2V4N22R3QVTYAJMWFK2U2O6QXAZYM35Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QWP6UBFA5T6MOQPY2VDUG5YAJBFPYRFF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWDZONUHDYKBXTAIAGHSYQDEGORD2QT7/
- https://support.zabbix.com/browse/ZBX-20680
- https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html
Affected products (5)
- cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:frontend:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
More vulnerabilities in Zabbix Frontend
- CVE-2023-32725 — Critical (CVSS 9.6): The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The…
- CVE-2025-49643 — Medium (CVSS 6.5): An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending…
- CVE-2023-29457 — Medium (CVSS 6.3): Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The…
- CVE-2023-29456 — Medium (CVSS 5.7): URL validation scheme receives input from a user and then parses it to identify its various components. The validation…
- CVE-2023-29455 — Medium (CVSS 5.4): Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web…
- CVE-2023-29454 — Medium (CVSS 5.4): Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web…
All CVEs affecting Zabbix Frontend →
Other CWE-79 (Cross-site Scripting (XSS)) vulnerabilities
- CVE-2026-106102 — Critical (CVSS 10.0): Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only…
- CVE-2026-59167 — Critical (CVSS 10.0): SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11,…
- CVE-2026-85061 — Critical (CVSS 10.0): MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in…
- CVE-2025-49410 — Critical (CVSS 10.0): Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC…
- CVE-2024-47875 — Critical (CVSS 10.0): DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to…
- CVE-2024-6886 — Critical (CVSS 10.0): Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea…
Browse all CWE-79 (Cross-site Scripting (XSS)) vulnerabilities →