RULE(RULE ID:338590)

Rule General Information
Release Date: 2024-12-10
Rule Name: Zabbix api_jsonrpc.php SQL Injection Vulnerability (CVE-2024-42327)
Severity:
CVE ID:
Rule Protection Details
Description: Zabbix is an enterprise-class open source monitoring solution that provides distributed system monitoring and network monitoring capabilities based on a WEB interface. The addRelatedObjects function in the CUser class of Zabbix's front-end does not adequately validate and escape the input data, allowing a malicious user with API access to pass a customized input through the user.get API to trigger a SQL injection attack. The Vulnerability can then be exploited to enhance permissions or access sensitive data. The affected versions are Zabbix 6.0.0-6.0.31, Zabbix 6.4.0-6.4.16, and Zabbix 7.0.0.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please go to the official website to download the secure version: https://support.zabbix.com/browse/ZBX-25623