← back
CVE-2024-22120criticalobserved exploitationCWE-20

Time Based SQL Injection in Zabbix Server Audit Log

97Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.1epss 77%
from disclosure to weapon3 days
Published on NVDMay 17
1st PoC+3d
VulnCheck+306d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesVulnCheck
8 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
Zabbix · Zabbix
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.