Critical severity9.6NVD Advisory· Published Dec 18, 2023· Updated Jun 17, 2026
CVE-2023-32725
CVE-2023-32725
Description
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.21
- cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha3:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.zabbix.com/browse/ZBX-23854nvdVendor Advisory
News mentions
0No linked articles in our index yet.