logo

Zabbix urges upgrades after critical SQL injection bug disclosure

ID: 29cb41ea-eaa3-5715-a411-1d0076268782

STIX ID: report--29cb41ea-eaa3-5715-a411-1d0076268782

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-11-29

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Zabbix disclosed a critical SQL injection (CVE-2024-42327, CVSSv3 9.9) in its CUser.addRelatedObjects/CUser.get API path that allows non-admin users with API access to escalate privileges and potentially fully compromise affected systems; users should upgrade affected 6.0.x, 6.4.x, and 7.0.0 installations to the provided patch releases to mitigate risk, and the vulnerability is concerning given Zabbix's wide enterprise customer base.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.