Логотип exploitDog
bind: "CVE-2024-42327"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-42327"

Количество 9

Количество 9

ubuntu логотип

CVE-2024-42327

7 месяцев назад

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVSS3: 9.9
EPSS: Высокий
nvd логотип

CVE-2024-42327

7 месяцев назад

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVSS3: 9.9
EPSS: Высокий
debian логотип

CVE-2024-42327

7 месяцев назад

A non-admin user account on the Zabbix frontend with the default User ...

CVSS3: 9.9
EPSS: Высокий
github логотип

GHSA-gx59-7g62-6xhg

7 месяцев назад

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVSS3: 9.9
EPSS: Высокий
fstec логотип

BDU:2024-10543

7 месяцев назад

Уязвимость функции addRelatedObjects универсальной системы мониторинга Zabbix, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.9
EPSS: Высокий
redos логотип

ROS-20241212-24

6 месяцев назад

Уязвимость zabbix7-lts-server-pgsql

CVSS3: 9.9
EPSS: Высокий
redos логотип

ROS-20241212-22

6 месяцев назад

Уязвимость zabbix7-lts-server-mysql

CVSS3: 9.9
EPSS: Высокий
redos логотип

ROS-20241212-04

6 месяцев назад

Уязвимость zabbix-lts-server-pgsql

CVSS3: 9.9
EPSS: Высокий
redos логотип

ROS-20241212-02

6 месяцев назад

Уязвимость zabbix-lts-server-mysql

CVSS3: 9.9
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-42327

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVSS3: 9.9
87%
Высокий
7 месяцев назад
nvd логотип
CVE-2024-42327

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVSS3: 9.9
87%
Высокий
7 месяцев назад
debian логотип
CVE-2024-42327

A non-admin user account on the Zabbix frontend with the default User ...

CVSS3: 9.9
87%
Высокий
7 месяцев назад
github логотип
GHSA-gx59-7g62-6xhg

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVSS3: 9.9
87%
Высокий
7 месяцев назад
fstec логотип
BDU:2024-10543

Уязвимость функции addRelatedObjects универсальной системы мониторинга Zabbix, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.9
87%
Высокий
7 месяцев назад
redos логотип
ROS-20241212-24

Уязвимость zabbix7-lts-server-pgsql

CVSS3: 9.9
87%
Высокий
6 месяцев назад
redos логотип
ROS-20241212-22

Уязвимость zabbix7-lts-server-mysql

CVSS3: 9.9
87%
Высокий
6 месяцев назад
redos логотип
ROS-20241212-04

Уязвимость zabbix-lts-server-pgsql

CVSS3: 9.9
87%
Высокий
6 месяцев назад
redos логотип
ROS-20241212-02

Уязвимость zabbix-lts-server-mysql

CVSS3: 9.9
87%
Высокий
6 месяцев назад

Уязвимостей на страницу