Zabbix
cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*, +1 more
- >= 7.4.0, <= 7.4.6
A vulnerability exists in the Zabbix Frontend 'validate' action, allowing unauthenticated attackers to blindly instantiate arbitrary PHP classes. While the impact may vary depending on the environment setup, it currently appears to be limited.
Exploitation of this vulnerability could lead to unauthorized instantiation of PHP classes, potentially allowing for further exploitation depending on the instantiated classes and the environment.
Users are advised to update to Zabbix version 7.4.7, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.