CVE-2024-36465: Zabbix
High severity, CVSS 8.8. EPSS: 39.9% chance of exploitation in the next 30 days.
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
Affected products
- Zabbix Zabbix: from 7.0.0, up to and including 7.0.7; from 7.2.0, before 7.2.2 (fixed in 7.2.2); version 7.0.8 only
Published 2025-04-02. Last modified 2026-06-17.