vendor:
Zabbix
by:
Todor Donev
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Zabbix
Affected Version From: Zabbix 4.4
Affected Version To: Zabbix 4.4
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux Apache/2 PHP/7.2
2019
Zabbix 4.4 – Authentication Bypass
This exploit allows an attacker to bypass authentication in Zabbix 4.4. The exploit works by sending a specially crafted payload to the server, which sets a cookie that allows the attacker to bypass authentication. The exploit was tested on Linux Apache/2 PHP/7.2.
Mitigation:
Ensure that authentication is properly implemented and that all users are authenticated before allowing access to the system.