CVE-2024-22120
critical · 9.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
9.1
CVSS
76.6%
EPSS (exploit prob.)
100th
EPSS percentile
2024-05-17
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zabbix | zabbix | >= 6.0.0, < 6.0.28 |
| zabbix | zabbix | >= 6.4.0, < 6.4.13 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
| zabbix | zabbix | 7.0.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-22120