« Back to list

CVE-2023-32725

Status: ModifiedHigh (8.8)—

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-32725",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zabbix.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@zabbix.com",
      "affectedData": [
        {
          "repo": "https://git.zabbix.com/",
          "vendor": "Zabbix",
          "modules": [
            "Server",
            "Web service"
          ],
          "product": "Zabbix",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.0.22rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.0.0 ",
              "versionType": "git",
              "lessThanOrEqual": "6.0.21"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.4.7rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.4.0",
              "versionType": "git",
              "lessThanOrEqual": "6.4.6"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.0.0alpha4",
                  "status": "unaffected"
                }
              ],
              "version": "7.0.0alpha1 ",
              "versionType": "git",
              "lessThanOrEqual": "7.0.0alpha3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-18T10:15:06.550",
  "references": [
    {
      "url": "https://support.zabbix.com/browse/ZBX-23854",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zabbix.com"
    },
    {
      "url": "https://support.zabbix.com/browse/ZBX-23854",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zabbix.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-565"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-565"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user."
    },
    {
      "lang": "es",
      "value": "El sitio web configurado en el widget de la URL recibirá una cookie de sesión al probar o ejecutar informes programados. La cookie de sesión recibida se puede utilizar para acceder a la interfaz como usuario particular."
    }
  ],
  "lastModified": "2026-06-17T05:59:27.780",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F99748EE-AE9C-4210-ABCD-10A5E6E7E58E",
              "versionEndIncluding": "6.0.21",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86A23392-9192-4CCA-BC7C-C4EEFB2C2B97",
              "versionEndIncluding": "6.4.6",
              "versionStartIncluding": "6.4.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DC55403-7711-4719-A309-2616586ED479"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BB0DFCF-6ED3-4BA3-8B3F-D1F6D06A08DB"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B17E6DD-0DA4-4002-B2D2-C16EED6C97BA"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A064CA46-1D9A-434E-B099-B3477BA2D14D",
              "versionEndIncluding": "6.0.21",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD82A00A-587E-4C1F-80CC-474A4A1D4A07",
              "versionEndIncluding": "6.4.6",
              "versionStartIncluding": "6.4.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:7.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40AB0231-C1C8-4D97-96B7-E293DD7250A7"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:7.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E5DF882-2A9F-4881-A0F7-FFC804B65495"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:7.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79886648-EEC0-44B3-8788-2F0A65B1FB1A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@zabbix.com"
}