CVE 7.5 HIGH

Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host_CVE-2025-27240

7.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

Basic Information

ID CVE-2025-27240
Source Zabbix
Published Sep 12, 2025 at 10:33

Affected Product

Vendor Zabbix
Product Zabbix
Version 6.0.0
Affected Versions Zabbix Zabbix 6.0.0
Zabbix Zabbix 6.4.0
Zabbix Zabbix 7.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.