-
Type:
Defect (Security)
-
Resolution: Fixed
-
Priority:
Minor
-
None
-
Affects Version/s: 2.2.11
-
Component/s: Frontend (F)
hello ,
I would like to report a fault in the request parameter , it allows redirection to external links from happening , which would make it possible for an attacker , using the suitability of the field with zabbix application, phishing attacks.
Example:
Normal request :
http: //server/zabbix/index.php?request=hosts.php
Malicious request :
http: //server/zabbix/index.php?request=http://fakepage/hosts.php
POC attached a video.
- duplicates
-
ZBX-13133 Multiple security issues in frontend
-
- Closed
-