← Back

CVE-2024-22120

Published: May 17, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

Affected (12)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 6.0.0 to 6.0.28
From 6.4.0 to 6.4.13
Version 7.0.0 alpha1
Version 7.0.0 alpha2
Version 7.0.0 alpha3
Version 7.0.0 alpha4
Version 7.0.0 alpha5
Version 7.0.0 alpha6
Version 7.0.0 alpha7
Version 7.0.0 alpha8
Version 7.0.0 alpha9
Version 7.0.0 beta1

References (2)

Source: security@zabbix.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory

Timeline

No history available yet.