← Back

CVE-2024-22117

nvd nist
Published: Nov 26, 2024Modified: Jun 17, 2026

JSON object

Loading...
2.2
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Exploitability: 0.7 / Impact: 1.4
Source: NVD

Description

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.

Affected (4)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 5.0.0 to 5.0.44
From 6.0.0 to 6.0.34
From 6.4.0 to 6.4.19
From 7.0.0 to 7.0.4

References (1)

Source: security@zabbix.com
Vendor Advisory

Timeline

No history available yet.