CVE-2024-42327
Published: Nov 27, 2024
Modified: Dec 4, 2024
CVSS v3.1
9.9
Description
A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.
| Vendor | Product | Versions |
|---|---|---|
Zabbix | Zabbix | affected 6.0.0 - <= 6.0.31affected 6.4.0 - <= 6.4.16affected 7.0.0 - <= 7.0.1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now