CVE-2023-29454 MEDIUM

CVE-2023-29454: Persistent XSS in the user form

Vendor Zabbix
Product Zabbix
Weakness CWE-20 · Input validation
Published July 13, 2023
Last update November 3, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.

Key dates

02Disclosure timeline

July 13, 2023 CVE published
November 3, 2025 Record updated