Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-23921

Опубликовано: 24 мар. 2026
Источник: debian
EPSS Низкий

Описание

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:7.0.22+dfsg-1package
zabbixfixed1:7.0.22+dfsg-1~deb13u1trixiepackage

Примечания

  • https://support.zabbix.com/browse/ZBX-27640

EPSS

Процентиль: 10%
0.00034
Низкий

Связанные уязвимости

nvd
9 дней назад

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.

github
9 дней назад

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.

EPSS

Процентиль: 10%
0.00034
Низкий