nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27240 CVE-2025-27240
HIGH
Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host
Record summary
CVE-2025-27240 has a selected CVSS score of 7.5 (high).
Description
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 13, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 6.0.0 to ≤ 6.0.33 | affected |
| 6.4.0 to ≤ 6.4.18 | affected | ||
| 7.0.0 to ≤ 7.0.3 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-26986