Home
MEDIUM: 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NDefault status
unknown
6.0.0 (git)
affected
7.0.0 (git)
affected
7.2.0 (git)
affected
7.4.0 (git)
affected
Description
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Problem types
CWE-405: Asymmetric Resource Consumption (Amplification)
Product status
6.0.0 (git)
7.0.0 (git)
7.2.0 (git)
7.4.0 (git)
Credits
Zabbix wants to thank Pamparau Sebastian (sebiee) for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-27284