CVE-2024-36466

CVSS V2 None CVSS V3 None
Description
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
Overview
  • CVE ID
  • CVE-2024-36466
  • Assigner
  • Zabbix
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-28T07:19:48.806Z
  • Last Modified Date
  • 2024-11-28T07:19:48.806Z
References
Reference URL Reference Tags
https://support.zabbix.com/browse/ZBX-25635
History
Created Old Value New Value Data Type Notes
2024-11-29 13:21:16 Added to TrackCVE