gaopeng2 8b0f1aae4e add: Zabbix CVE-2022-23131
add: Tenda uploadWewifiPic RCE
2022-02-24 14:54:43 +08:00

747 B

Zabbix Login Bypass (CVE-2022-23131)

Zabbix is an open source monitoring system. The system supports network monitoring, server monitoring, cloud monitoring and application monitoring, etc. A login bypass vulnerability exists in Zabbix that arises when SAML SSO authentication is enabled (not default). An unauthenticated malicious attacker could exploit the vulnerability to escalate privileges and gain administrator access to the Zabbix frontend.

FOFA query rule: body="SAML" && (banner="zbx_session=" || header="zbx_session=")

Demo

Zabbix_Login_Bypass_CVE_2022_23131