Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like proto, combined with jQuery's unsafe element creation that traversed the prototype chain.
An authenticated Zabbix user could inject the malicious HTML into the Zabbix UI (Map page).
Update the affected components to their respective fixed versions.