Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
5.0.0 (git)
affected
6.0.0 (git)
affected
6.4.0 (git)
affected
7.0.0 (git)
affected
Description
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access.
Problem types
CWE-285 Improper Authorization
Product status
5.0.0 (git)
6.0.0 (git)
6.4.0 (git)
7.0.0 (git)
Credits
Zabbix wants to thank Márk Rákóczi for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-25614