CVE-2021-27927 Information
Jun 07, 2022
cve
Description
In Zabbix from 4.0.x before 4.0.28rc1 5.0.0alpha1 before 5.0.10rc1 5.2.x before 5.2.6rc1 and 5.4.0alpha1 before 5.4.0beta2 the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn’t have to know Zabbix user login credentials but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://support.zabbix.com/browse/ZBX-18942
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: