.. / CVE-2022-23131

Exploit for Zabbix - SAML SSO Authentication Bypass (CVE-2022-23131)

Description:

When SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor because a user login stored in the session was not verified.

Nuclei Template

View the template here CVE-2022-23131.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-23131.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-23131
https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage
https://support.zabbix.com/browse/ZBX-20350
https://github.com/1mxml/CVE-2022-23131
https://github.com/20142995/sectool