← Back

CVE-2024-22116

nvd nist
Published: Aug 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

Affected (15)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 6.4.9 to 6.4.15
Version 7.0.0 alpha1
Version 7.0.0 alpha2
Version 7.0.0 alpha3
Version 7.0.0 alpha4
Version 7.0.0 alpha5
Version 7.0.0 alpha6
Version 7.0.0 alpha7
Version 7.0.0 alpha8
Version 7.0.0 alpha9
Version 7.0.0 beta1
Version 7.0.0 beta2
Version 7.0.0 beta3
Version 7.0.0 rc1
Version 7.0.0 rc2

References (2)

Source: security@zabbix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.