CVE-2024-36465
CVE-2024-36465 is a SQL injection vulnerability in Zabbix, allowing a low-privilege user with API access to execute arbitrary SQL commands. The vulnerability resides in include/classes/api/CApiService.php
and is triggered via the groupBy
parameter. With an SVRS score of 36, while not critical, this vulnerability should still be addressed to prevent potential data breaches or unauthorized access. Although the CVSS score is 0, the 'In The Wild' tag suggests active exploitation, increasing the risk. Exploitation could lead to unauthorized data access, modification, or deletion. Decision-makers should prioritize patching Zabbix instances to mitigate this potential threat.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.