-
Defect (Security)
-
Resolution: Fixed
-
Major
-
None
-
None
-
None
| CVE ID | CVE-2025-27240 |
| CVSS score | 7.5 (High) |
| CVSS vector | CVSS:4.0/AV:N/AC:L/AT |
| Affected components | Server |
| Summary | Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host |
| Description | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. |
| Known attack vectors | The attacker needs to be a Zabbix administrator and also needs access to a host that is later auto-removed. |
| Affected and fix version/s | Affected: 6.0.0 - 6.0.33 → Fixed: 6.0.34 Affected: 6.4.0 - 6.4.18 → Fixed: 6.4.19 Affected: 7.0.0 - 7.0.3 → Fixed: 7.0.4 |
| Mitigation | Update the affected components to their respective fixed versions. |
| Workarounds | Disable any Autoregistration actions that remove hosts. |
| Acknowledgements | Zabbix wants to thank Grzegorz Muszyński (szerszen199) for submitting this report on the HackerOne bug bounty platform. |
- mentioned in
-
Page Loading...