CVE-2024-36465
02.04.2025, 06:15
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 7.0.0 ≤ 𝑥 ≤ 7.0.7 |
| zabbix | zabbix | 7.2.0 ≤ 𝑥 < 7.2.2 |
| zabbix | zabbix | 7.0.8:rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases