An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
Credits
Zabbix wants to thank barume for submitting this report on the HackerOne bug bounty platform.