ZeroHour

CVE-2024-22120

PoC
CVSS 3.1
8.8 high
EPSS
77%p100
Published
()
Modified
Description

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

Vendors
zabbix
Products
zabbix
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.