[ZBX-22985] Persistent XSS in the user form (CVE-2023-29454) Created: 2023 Jun 16  Updated: 2023 Dec 18  Resolved: 2023 Jun 20

Status: Closed
Project: ZABBIX BUGS AND ISSUES
Component/s: Frontend (F)
Affects Version/s: 4.0.45
Fix Version/s: 4.0.46rc1, 5.0.35rc1, 6.0.18rc1

Type: Defect (Security) Priority: Minor
Reporter: Maris Melnikovs (Inactive) Assignee: Zabbix Development Team
Resolution: Fixed Votes: 0
Labels: frontend, security-vulnerabilities
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Duplicate

 Description   
Mitre ID CVE-2023-29454
CVSS score 5.4
Severity Medium
Summary Persistent XSS in the user form
Description Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
Known attack vectors Vulnerability was found on “Users” section in “Media” tab in “Send to” form field. When new media is created with malicious code included into field “Send to” then it will execute when editing the same media.
Patch provided  No
Component/s Frontend
Affected version/s and fix version/s
  • Affected: 4.0.45, 5.0.33, 6.0.16
  • Fix: 4.0.46rc1, 5.0.35rc1, 6.0.18rc1
Fix compatibility tests  
Resolution Fixed
Workarounds None
Acknowledgements  -

Generated at Fri Apr 18 10:09:34 EEST 2025 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.