6
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Basic Information
ID
CVE-2025-49643
Source
Zabbix
Published
Dec 1, 2025 at 13:05
Modified
Dec 1, 2025 at 14:34
Affected Product
Vendor
Zabbix
Product
Zabbix
Version
6.0.0
Affected Versions
Zabbix Zabbix 6.0.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.2.0
Zabbix Zabbix 7.4.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.2.0
Zabbix Zabbix 7.4.0