CVE-2024-36465

Publication date

2025-04-02 06:11:26

Family

Zabbix

State

PUBLISHED

Description

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.