peter bassill · operator
$ cve CVE-2024-42327 JSON

CVE-2024-42327 EXPLOIT

9.9
CRITICAL · CVSS 3.1 · EPSS 78.7% (pctl 100)

Patch early

A public exploit exists.

Description

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS78.72% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2024-11-27
Last modified2026-06-17

Affected (1)

VendorProduct
zabbixzabbix

Public exploits

SourceTitleDate
exploit-dbZabbix 7.0.0 - SQL Injection2025-04-16

References

→ the Explorer  ·  watch your stack  ·  NVD