CVE-2024-36465
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
HIGH · CVSS 8.8
EPSS 0.02177
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0