← back
CVE-2022-46768mediumCWE-20

File name information disclosure vulnerability in Zabbix Web Service Report Generation

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 48%
exploitation probability
48%top 1% of all CVEs
observed exploitation
nono source reports it
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N