← Back to browse · API

CVE-2022-23134

Severity
LOW
CVSS
3.7
EPSS
0.84657
Risk score
69.43
CISA KEV
Yes
PoC
No
Published
2022-01-13
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-28225, GHSA-MV97-QJ5H-25F3
Products
DependencyTrack:Frontend 5.4.0 - 5.4.8, Zabbix:Frontend
Sources
cisa.gov CVE-2022-23134
euvd EUVD-2022-28225

Description

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

References