← Back to browse · API

CVE-2024-22116

Severity
CRITICAL
CVSS
9.9
EPSS
0.01603
Risk score
40.16
CISA KEV
No
PoC
No
Published
2024-08-09
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2024-19712, GHSA-3WCH-5XM2-547F
Products
Zabbix:Zabbix 6.4.9 ≤6.4.15, Zabbix:Zabbix 7.0.0alpha1 ≤7.0.0rc2
Sources
euvd EUVD-2024-19712

Description

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

References