Zabbix urges upgrades after critical SQL injection bug disclosure
ID: 29cb41ea-eaa3-5715-a411-1d0076268782
STIX ID: report--29cb41ea-eaa3-5715-a411-1d0076268782
Feed Name: The Register (Security)
Threat Score
Zabbix disclosed a critical SQL injection (CVE-2024-42327, CVSSv3 9.9) in its CUser.addRelatedObjects/CUser.get API path that allows non-admin users with API access to escalate privileges and potentially fully compromise affected systems; users should upgrade affected 6.0.x, 6.4.x, and 7.0.0 installations to the provided patch releases to mitigate risk, and the vulnerability is concerning given Zabbix's wide enterprise customer base.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
