PoC Index

CVE-2024-22120

CRITICAL 9.1EPSS 76.6%

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
76.62% chance of exploitation in the next 30 days, 100th percentile
Nuclei
critical · CWE-20
Published
2024-05-17
Updated
2024-08-01

Proof-of-concept exploits (7)

Nuclei templates (1)

References

Related