Executive brief
An improper access control vulnerability in Zabbix Frontend allows unauthenticated users to access certain steps of the setup.php file after the initial setup process. Malicious actors can bypass step checks to potentially modify the configuration of the Zabbix Frontend.
Affected products
- Zabbix Frontend
Timeline
- 2022-02-22: disclosed
- 2022-02-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog