A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.
References
Link | Resource |
---|---|
https://support.zabbix.com/browse/ZBX-25623 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-11-27 12:15
Updated : 2024-11-27 12:15
NVD link : CVE-2024-42327
Mitre link : CVE-2024-42327
CVE.ORG link : CVE-2024-42327
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')