CVE-2023-32725: Zabbix Frontend
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
Affected products
- Zabbix Frontend: from 6.0.0, up to and including 6.0.21; from 6.4.0, up to and including 6.4.6; version 7.0.0 only
- Zabbix Zabbix Server: from 6.0.0, up to and including 6.0.21; from 6.4.0, up to and including 6.4.6; version 7.0.0 only
Published 2023-12-18. Last modified 2026-06-17.