-
Defect (Security)
-
Resolution: Fixed
-
Major
-
None
-
None
-
None
CVE ID | CVE-2025-27240 |
CVSS score | 7.5 (High) |
CVSS vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Affected components | Server |
Summary | Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host |
Description | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. |
Known attack vectors | The attacker needs to be a Zabbix administrator and also needs access to a host that is later auto-removed. |
Affected and fix version/s | Affected: 6.0.0 - 6.0.33 → Fixed: 6.0.34 Affected: 6.4.0 - 6.4.18 → Fixed: 6.0.19 Affected: 7.0.0 - 7.0.3 → Fixed: 7.0.4 |
Mitigation | Update the affected components to their respective fixed versions. |
Workarounds | Disable any Autoregistration actions that remove hosts. |
Acknowledgements | Zabbix wants to thank Grzegorz Muszyński (szerszen199) for submitting this report on the HackerOne bug bounty platform. |
- mentioned in
-
Page Loading...