Home
HIGH: 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
7.0.0 (git)
affected
7.2.0 (git)
affected
Description
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
7.0.0 (git)
7.2.0 (git)
Credits
Zabbix wants to thank cynau1t for submitting this report on the HackerOne bug bounty platform
References
support.zabbix.com/browse/ZBX-26257
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.