Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36465

Опубликовано: 02 апр. 2025
Источник: debian

Описание

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:7.0.9+dfsg-1package
zabbixnot-affectedbookwormpackage
zabbixnot-affectedbullseyepackage

Примечания

  • https://support.zabbix.com/browse/ZBX-26257

  • Fixed by: https://github.com/zabbix/zabbix/commit/529eec6957abff2f687c39219fa7a4a739d094c1 (7.0.8rc2)

  • "groupBy" feature introduced with https://github.com/zabbix/zabbix/commit/8a4e40ca6ff3b6be5c4144aaabf25cba315f5f4c (7.0.0alpha3)

Связанные уязвимости

ubuntu
3 месяца назад

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

nvd
3 месяца назад

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

CVSS3: 8
redos
около 2 месяцев назад

Уязвимость zabbix7-lts-server-mysql

CVSS3: 8
redos
около 2 месяцев назад

Уязвимость zabbix7-lts-server-pgsql

github
3 месяца назад

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.