A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.
PoC: Zabbix-CVE-2024-42327-SQL-Injection-RCE
Zabbix CVE-2024-42327 PoC
PoC: CVE-2024-42327
PoC for CVE-2024-42327 / ZBX-25623
PoC: analise-vulnerabilidades-zabbix-notebooklm
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque até RCE e miniguia de hardening
PoC: CVE-2024-42327_Zabbix_SQLi
This is for educational porpuses only. Please do not use agains unathorized systems.
PoC: CVE-2024-42327
POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE
PoC: CVE-2024-42327
writeup cve-2024-42327
PoC: CVE-2024-42327_Zabbix_SQLI
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
PoC: cve-2024-42327
cve-2024-42327 ZBX-25623
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free