CVE-2021-27927

CVE-2021-27927

In Zabbix before 4.0.28rc1, 5.x before 5.0.8rc1, 5.1.x and 5.2.x before 5.2.4rc1, and 5.3.x and 5.4.x before 5.4.0alpha1, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method.

Source: CVE-2021-27927

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다