A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
| Software | From | Fixed in |
|---|---|---|
| zabbix / zabbix | 7.0.0 | 7.0.7.x |
| zabbix / zabbix | 7.2.0 | 7.2.2 |
| zabbix / zabbix | 7.0.8-rc1 | 7.0.8-rc1.x |