← back
CVE-2024-22120criticalobserved exploitationCWE-20

Time Based SQL Injection in Zabbix Server Audit Log

97Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.1epss 77%
from disclosure to weapon3 days
Published on NVDMay 17
1st PoC+3d
VulnCheck+306d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesVulnCheck
8 public exploit(s)
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
Zabbix · Zabbix
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.