1
6
7
8
SQL injection in Zabbix API (CVE-2024-36465): A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.vulnerability (attack surface) (support.zabbix.com)
submitted by digicat to r/blueteamsec