Zabbix Flaws Allow Monitored Hosts to Hijack Admin Dashboards
ID: 7f402c18-1192-5193-81b6-8f8228d4dd70
STIX ID: report--7f402c18-1192-5193-81b6-8f8228d4dd70
Feed Name: securityonline.info
Threat Score
Zabbix released security patches for three vulnerabilities: two high-severity stored XSS issues in the Frontend (Host Navigator and Item History widgets) enabling execution of attacker-supplied JavaScript by administrators, and a medium-severity injection flaw in Agent 2's Oracle plugin that can redirect connections to attacker-controlled servers and leak Oracle credentials; fixed versions and mitigations are listed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
