CVE-2024-22120
Time Based SQL Injection in Zabbix Server Audit Log
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Zabbix · ZabbixPoCs públicas encontradas — 4
githubgithub.com/W01fh4cker/CVE-2024-22120-RCE★ 140githubgithub.com/isPique/CVE-2024-22120-RCE-with-gopher★ 3githubgithub.com/g4nkd/CVE-2024-22120-RCE-with-gopher★ 3githubgithub.com/darkbytehunter/CVE-2024-22120-RCE-with-gopher★ 1⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://support.zabbix.com/browse/ZBX-24505