vendor:
Zabbix
by:
Milad Khoshdel
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Zabbix
Affected Version From: 2.x
Affected Version To: 4.x
Patch Exists: NO
Related CWE: N/A
CPE: a:zabbix:zabbix
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux Apache/2 PHP/7.2
2019
Zabbix 4.2 – Authentication Bypass
Attacker can bypass login page and access to dashboard page and create Dashboard/Report/Screen/Map without any Username/Password and anonymously. All Created elements [Dashboard/Report/Screen/Map] is accessible by other users and admin.
Mitigation:
Ensure that authentication is properly implemented and enforced for all users.