Impact
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, enabling a javascript: URL to be executed in the browser. This allows a crafted media type configuration, delivered as an import file, to run arbitrary JavaScript with the privileges of a Super Admin who grants consent. The affected weakness is Cross‑Site Scripting, which can lead to privilege escalation, data theft, or further compromise of the Zabbix instance.
Affected Systems
Zabbix Zabbix is affected. The vulnerability resides in the OAuth configuration form used for email media type setups. Specific impacted versions are not listed in the advisory, so all current releases that have not applied the fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA's KEV catalog. Exploitation requires an attacker to provide a malicious import file that contains a javascript: URL in the Authorization endpoint field. The attack vector is inferred to be through authorized super‑admin access to the import feature, so it is limited to scenarios where an attacker can coerce or compromise a Super Admin account.
OpenCVE Enrichment