A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
2025-09-12T11:15:31.633
2025-10-08T14:53:38.077
Analyzed
CVSSv3.1: 7.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zabbix | zabbix | < 6.0.34 | Yes |
| Application | zabbix | zabbix | < 6.4.19 | Yes |
| Application | zabbix | zabbix | < 7.0.4 | Yes |