6.8
CVSSv2

CVE-2021-27927

Published: 03/03/2021 Updated: 12/04/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Zabbix from 4.0.x prior to 4.0.28rc1, 5.0.0alpha1 prior to 5.0.10rc1, 5.2.x prior to 5.2.6rc1, and 5.4.0alpha1 prior to 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix

Vendor Advisories

In Zabbix from 40x before 4028rc1, 500alpha1 before 5010rc1, 52x before 526rc1, and 540alpha1 before 540beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism In Zabbix from 40x before 4028rc1, 500alpha1 before 5010rc1, 52x before 526rc1, and 540alpha1 before 540beta2, the CControlle ...