Loading HuntDB...

GHSA-gx59-7g62-6xhg

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

Related CVEs

Key Information

GHSA ID
GHSA-gx59-7g62-6xhg
Published
November 27, 2024 12:31 PM
Last Modified
November 27, 2024 12:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.