CVE-2023-32725: Zabbix Frontend

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

Affected products

  • Zabbix Frontend: from 6.0.0, up to and including 6.0.21; from 6.4.0, up to and including 6.4.6; version 7.0.0 only
  • Zabbix Zabbix Server: from 6.0.0, up to and including 6.0.21; from 6.4.0, up to and including 6.4.6; version 7.0.0 only

Published 2023-12-18. Last modified 2026-06-17.