Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15803
Reference (s):
- FEDORA:FEDORA-2020-02cf7850ca
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/2ZHHIUYIVA5GZYLKW6A5G6HRELPOBZFE/
- FEDORA:FEDORA-2020-519516feec
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/TIRIMOXH6GSBAANDCB3ANLJK4CRLWRXT/
- https://support.zabbix.com/browse/ZBX-18057

