
CVE-2022-23131漏洞利用工具开箱即用。
CVE-2022-23131(Unsafe Session Storage)
Zabbix vulnerability (CVE-2022-23131), I accidentally obtained a Zabbix server of a foreign company. Zabbix Sia Zabbix is an open-source monitoring system developed by Zabbix SIA (Zabbix Sia) from Latvia. This system supports network monitoring, server monitoring, cloud monitoring, application monitoring, etc. Zabbix Frontend has a security vulnerability. The vulnerability stems from the fact that when SAML SSO authentication (non-default) is enabled, malicious actors can modify session data because the user login stored in the session is not verified. An unauthenticated malicious attacker may exploit this issue to escalate privileges and gain administrative access to the Zabbix frontend.
5.4.8
5.0.18
4.0.36
