6.1
CVSSv3

CVE-2020-15803

Published: 17/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Zabbix prior to 3.0.32rc1, 4.x prior to 4.0.22rc1, 4.1.x up to and including 4.4.x prior to 4.4.10rc1, and 5.x prior to 5.0.2rc1 allows stored XSS in the URL Widget.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 5.0.2

zabbix zabbix

zabbix zabbix 4.4.10

zabbix zabbix 4.0.22

zabbix zabbix 3.0.32

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 9.0

opensuse leap 15.1

opensuse leap 15.2

opensuse backports sle-15

Vendor Advisories

Debian Bug report logs - #966146 zabbix: CVE-2020-15803 Package: src:zabbix; Maintainer for src:zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 23 Jul 2020 19:33:01 UTC Severity: important Tags: security, upstream Found in version zabbix/1:501+dfsg-1 ...

Exploits

Zabbix version 500 suffers from a persistent cross site scripting vulnerability ...