CVE-2024-42327

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.
References
Link Resource
https://support.zabbix.com/browse/ZBX-25623 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*

History

08 Oct 2025, 16:41

Type Values Removed Values Added
CPE cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
References () https://support.zabbix.com/browse/ZBX-25623 - () https://support.zabbix.com/browse/ZBX-25623 - Vendor Advisory
First Time Zabbix zabbix
Zabbix

Information

Published : 2024-11-27 12:15

Updated : 2025-10-08 16:41


NVD link : CVE-2024-42327

Mitre link : CVE-2024-42327

CVE.ORG link : CVE-2024-42327


JSON object : View

Products Affected

zabbix

  • zabbix
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')