Zabbix
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.0.21
- >= 7.2.0, <= 7.2.14
- >= 7.4.0, <= 7.4.5
A blind SQL injection vulnerability has been identified in the Zabbix API, specifically in versions 7.0.0 through 7.0.21, 7.2.0 through 7.2.14, and 7.4.0 through 7.4.5. This vulnerability allows a low-privilege user with API access to execute arbitrary SQL select statements via the sortfield parameter. Although the results of these queries are not returned directly, an attacker can use time-based techniques to exfiltrate database information. This could potentially lead to the disclosure of session identifiers and compromise of administrator accounts.
Exploitation of this vulnerability could result in unauthorized access to database information, including session identifiers, which could be used to compromise administrator accounts.
Users can update to Zabbix versions 7.0.22, 7.2.15, or 7.4.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.