CVE-2024-36463
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.82%
- CWE
- CWE-767
- Published
- 2024-11-26
- Last modified
- 2026-03-13
Affected products
- Zabbix Zabbix
- Zabbix Zabbix
- Zabbix Zabbix
- Zabbix Zabbix
Weakness type
Related vulnerabilities
- CVE-2024-34162 — The web interface of the affected devices is designed to hide the LDAP credentials even for...
- CVE-2020-26868 — ARC Informatique PcVue Access to Critical Private Variable via Public Method
- CVE-2016-8380 — The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without...