Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NZabbix Web Service Report Generation
APPZabbix6.0.0 – 6.0.116.2.0 – 6.2.5Zabbix Agent2
APPZabbix< 6.0.126.2.0 – 6.2.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-29453CRITICAL9.8PL ✓same product
Wstrzyknięcie kodu JavaScript w szablonach Go w Zabbix-Agent2
CVE-2022-22704CRITICAL9.8PL ✓same product
Privilege escalation do root w zabbix-agent2 na Alpine Linux
CVE-2023-32728MEDIUM4.6same product
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell com...
CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓same vendor
Zabbix SAML SSO — privilege escalation do konta administratora
CVE-2024-42327CRITICAL9.9PL ✓same vendor
SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień