A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
2025-04-02T06:15:34.130
2025-10-08T15:31:44.823
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zabbix | zabbix | ≤ 7.0.7 | Yes |
| Application | zabbix | zabbix | < 7.2.2 | Yes |
| Application | zabbix | zabbix | 7.0.8 | Yes |