CRITICAL🇵🇱 Wersja polska

CVE-2024-22120

CVSS 9.1v3.1pub. 2024-05-17upd. 2025-10-08

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

🤖 AI Analysis
How it works

When Zabbix Server executes a configured script, an entry containing the 'clientip' field is added to the 'Audit Log' table. This field is not validated or sanitized before being inserted into the SQL query. An attacker can inject malicious SQL payload into the 'clientip' value, allowing a time-based blind SQL injection attack — a technique that extracts data from the database by measuring server response times.

Impact

An attacker with high-level privileges can gain unauthorized access to sensitive data stored in the Zabbix database, and potentially also modify or destroy data (according to CVSS vector: high confidentiality, integrity and availability breach in the modified domain).

Mitigation & patch

Patches available from the vendor should be applied according to references (https://support.zabbix.com/browse/ZBX-24505). As a temporary measure, it is recommended to restrict access to the Zabbix administrative interface only to trusted networks and IP addresses.

Who is affected

Zabbix Server — versions indicated in vendor references (ticket ZBX-24505)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Zabbix

    APP
    Zabbix
    7.0.06.0.0 – 6.0.28 (excl.)6.4.0 – 6.4.13 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓same product

Zabbix SAML SSO — privilege escalation do konta administratora

CVE-2024-42327CRITICAL9.9PL ✓same product

SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień

CVE-2024-42330CRITICAL9.1PL ✓same product

Zabbix: niekodowane nagłówki HTTP umożliwiają dostęp do ukrytych właściwości obiektów

CVE-2024-22116CRITICAL9.9PL ✓same product

Zabbix: RCE przez brak escapowania parametrów skryptu Ping

CVE-2024-36461CRITICAL9.1PL ✓same product

Zabbix: modyfikacja wskaźników pamięci w silniku JavaScript (RCE/DoS)