← All CVEs

CVE-2024-22120

critical · 9.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

9.1
CVSS
76.6%
EPSS (exploit prob.)
100th
EPSS percentile
2024-05-17
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
zabbixzabbix>= 6.0.0, < 6.0.28
zabbixzabbix>= 6.4.0, < 6.4.13
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0
zabbixzabbix7.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-22120