Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
When Zabbix Server executes a configured script, an entry containing the 'clientip' field is added to the 'Audit Log' table. This field is not validated or sanitized before being inserted into the SQL query. An attacker can inject malicious SQL payload into the 'clientip' value, allowing a time-based blind SQL injection attack — a technique that extracts data from the database by measuring server response times.
An attacker with high-level privileges can gain unauthorized access to sensitive data stored in the Zabbix database, and potentially also modify or destroy data (according to CVSS vector: high confidentiality, integrity and availability breach in the modified domain).
Patches available from the vendor should be applied according to references (https://support.zabbix.com/browse/ZBX-24505). As a temporary measure, it is recommended to restrict access to the Zabbix administrative interface only to trusted networks and IP addresses.
Zabbix Server — versions indicated in vendor references (ticket ZBX-24505)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HZabbix
APPZabbix7.0.06.0.0 – 6.0.28 (excl.)6.4.0 – 6.4.13 (excl.)
Related vulnerabilities
Zabbix SAML SSO — privilege escalation do konta administratora
SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień
Zabbix: niekodowane nagłówki HTTP umożliwiają dostęp do ukrytych właściwości obiektów
Zabbix: RCE przez brak escapowania parametrów skryptu Ping
Zabbix: modyfikacja wskaźników pamięci w silniku JavaScript (RCE/DoS)