Unrated severityCISA KEVNVD Advisory· Published Jan 13, 2022· Updated Oct 21, 2025
Possible view of the setup pages by unauthenticated users if config file already exists
CVE-2022-23134
Description
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
Affected products
1- Zabbix/Frontendv5Range: 5.4.0 - 5.4.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/mitrevendor-advisoryx_refsource_FEDORA
- lists.debian.org/debian-lts-announce/2022/02/msg00008.htmlmitremailing-listx_refsource_MLIST
- support.zabbix.com/browse/ZBX-20384mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.