Zabbix
cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*, +1 more
- >= 6.0.0, <= 6.0.41
- >= 7.0.0, <= 7.0.18
- >= 7.2.0, <= 7.2.12
- >= 7.4.0, <= 7.4.2
A denial-of-service vulnerability has been identified in the Zabbix frontend, specifically in versions 6.0.0 through 6.0.41, 7.0.0 through 7.0.18, 7.2.0 through 7.2.12, and 7.4.0 through 7.4.2. This vulnerability allows an authenticated user, including guests, to cause excessive CPU load on the web server. The issue arises from sending specially crafted parameters to 'imgstore.php', leading to potential service disruption.
Exploitation of this vulnerability can cause a significant increase in CPU usage on the web server, potentially leading to a denial-of-service condition where the server becomes unresponsive or slow to respond to legitimate requests.
Users can update to Zabbix versions 6.0.42, 7.0.19, 7.2.13, or 7.4.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.