Vulnerability Database

317,182

Total vulnerabilities in the database

CVE-2024-22120

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

  • Published: May 17, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-22120
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.1
  • AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CWEs:

Software From Fixed in
zabbix / zabbix 6.0.0 6.0.28
zabbix / zabbix 6.4.0 6.4.13
zabbix / zabbix 7.0.0-alpha1 7.0.0-alpha1.x
zabbix / zabbix 7.0.0-alpha2 7.0.0-alpha2.x
zabbix / zabbix 7.0.0-alpha3 7.0.0-alpha3.x
zabbix / zabbix 7.0.0-alpha4 7.0.0-alpha4.x
zabbix / zabbix 7.0.0-alpha5 7.0.0-alpha5.x
zabbix / zabbix 7.0.0-alpha6 7.0.0-alpha6.x
zabbix / zabbix 7.0.0-alpha7 7.0.0-alpha7.x
zabbix / zabbix 7.0.0-alpha8 7.0.0-alpha8.x
zabbix / zabbix 7.0.0-alpha9 7.0.0-alpha9.x
zabbix / zabbix 7.0.0-beta1 7.0.0-beta1.x