CVE-2024-22120 is a SQL injection vulnerability in Zabbix Server audit logging. When a configured script command is executed, Zabbix Server creates an Audit Log entry. The clientip field is not sanitized before it is used in the audit-log operation, allowing SQL injection through that field and enabling time-based blind SQL injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2024-22120 against Zabbix. It contains only two files: a README with usage instructions and exploit.py, the main exploit entry point. The script is not part of a larger framework. The exploit chains multiple capabilities. First, it abuses the /contact endpoint with an XXE payload that references a php://filter wrapper to trigger an internal webhook request. That webhook is used as a gopher-based SSRF primitive to reach internal services. One target is zabbix-server:10051, where the script sends a crafted Zabbix protocol message containing a SQL injection in the clientip field. The SQLi is time-based and iterates over hexadecimal characters to recover the 32-character admin session ID from the sessions table. After obtaining the admin session, the exploit pivots to the internal Zabbix web service at zabbix-web:8080 and sends raw HTTP POST requests to /api_jsonrpc.php via gopher. It invokes script.create to register a command containing a hardcoded bash reverse shell, then invokes script.execute to run it. The main exploit capabilities are: internal request forgery via XXE+gopher, blind time-based SQL injection for admin session extraction, authenticated API abuse using the stolen admin session, and remote code execution through Zabbix script execution. The payload is operational rather than highly flexible because the reverse shell callback is hardcoded to 10.0.46.27:5555 and the execution hostid in the final stage is also hardcoded to 10084. The script requires operator-supplied values for the target IP, low-privileged sid, accessible hostid, PHPSESSID, and timing thresholds. It is a real exploit, not merely a detector, and its end goal is full command execution with a reverse shell on the Zabbix server.
This repository contains a Python exploit (exploit.py) targeting Zabbix version 6.0.27 (CVE-2024-22120) for remote code execution. The exploit leverages an XXE vulnerability to perform internal gopher requests, which are then used to exploit a time-based SQL injection on the Zabbix server's internal service (zabbix-server:10051). The attack extracts the admin session ID, creates a malicious script on the Zabbix web interface (zabbix-web:8080), and executes it to spawn a reverse shell to the attacker's machine (default: 10.0.46.27:5555). The exploit requires the attacker to have a low-privileged session ID, host ID, and PHPSESSID, and to be able to reach the Zabbix web interface. The repository consists of a detailed README.md and a single exploit script (exploit.py), which is the main entry point and contains all the exploit logic. The exploit is operational and provides a working reverse shell payload, but requires some manual setup (listener, session IDs, etc.).
This repository provides a toolkit for exploiting CVE-2024-22120 in Zabbix (versions 6.0.0-6.0.27, 6.4.0-6.4.12, 7.0.0alpha1). It contains three main Python scripts: 1. CVE-2024-22120-LoginAsAdmin.py: Performs a time-based SQL injection via the Zabbix server's command interface to extract the admin session ID and session key, then forges a valid admin session cookie, allowing privilege escalation from a low-privilege user to admin. 2. CVE-2024-22120-RCE.py: Uses a similar SQL injection to extract the admin session ID, then leverages the Zabbix API to create, update, and execute scripts on the server, allowing arbitrary OS command execution as the Zabbix user. The script provides an interactive shell for command execution. 3. CVE-2024-22120-Webshell.py: Attempts to upload a webshell to the Zabbix server by echoing base64-decoded content to a file in the Zabbix web directory. This requires admin privileges and is often unsuccessful due to permission restrictions, but if successful, provides a persistent webshell. The README.md explains affected versions, usage instructions, and prerequisites (low-privilege user with script execution rights). The attack vector is network-based, targeting the Zabbix server's TCP and HTTP interfaces. The scripts require the attacker to know or obtain a valid session ID and host ID, which can be captured from network traffic or by exploiting the SQL injection. The toolkit enables privilege escalation, remote command execution, and (in rare cases) webshell upload on vulnerable Zabbix installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.