Showing 1 vulnerability on this page for zabbix_server

Signals CISA KEV Ransomware Nuclei
Zabbix vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Time Based SQL Injection in Zabbix Server Audit Log

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CWE-20May 17, 20241 related artifact
CVSS9.1v3.1EPSS76.6%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX