CVE-2024-42327 is a critical SQL injection vulnerability in the Zabbix frontend. The flaw is caused by insufficient validation of user-supplied input in the CUser class, specifically in the addRelatedObjects function, which is invoked from the CUser.get API method. Because CUser.get is available to users with API access, a non-administrative authenticated user, including one with the default User role if API access is permitted, can reach the vulnerable code path. Successful exploitation allows injection of SQL commands through crafted API requests and can be used to escalate privileges and compromise the affected Zabbix instance. Reported affected versions are Zabbix frontend 6.0.0 through 6.0.31, 6.4.0 through 6.4.16, and 7.0.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Single-file Python exploit that targets the Zabbix JSON-RPC API. The script uses the requests library and a hardcoded bearer token to authenticate to http://127.0.0.1/zabbix/api_jsonrpc.php, then performs three main actions: (1) calls host.get to enumerate available hosts, (2) calls script.create to register a new Zabbix script named 'pwn3' containing a bash reverse shell payload, and (3) calls script.execute to run that script against the first discovered host. The exploit is operational rather than a mere PoC because it includes a working payload, though the callback IP is left as a placeholder (LISTEN_IP). Repository structure is minimal: one Python file with top-level execution logic and a small helper function api() wrapping JSON-RPC POST requests. Main capability is authenticated remote code execution through legitimate Zabbix administrative functionality, resulting in a reverse shell from the managed host if permissions and execution conditions are met.
This repository contains a Python exploit script (sqliZabbix.py) targeting an authenticated SQL injection vulnerability in Zabbix 7.0.0. The exploit requires valid Zabbix user credentials and interacts with the Zabbix API endpoint (typically /zabbix/api_jsonrpc.php). It supports four main modes: leaking user hashes, leaking session tokens, executing arbitrary SQL queries, and achieving remote code execution (RCE) via a reverse shell (the latter requires an admin API token). The script is operational and automates the exploitation process, including authentication, SQL injection payload crafting, and (for RCE) the creation of a malicious Zabbix item that triggers a reverse shell. The repository is structured simply, with a single exploit script and a README providing detailed usage instructions and examples. No hardcoded IPs or domains are present; the target URL and attacker IP/port are provided as arguments.
This repository contains a working exploit for CVE-2024-42327, a critical privilege escalation and remote code execution vulnerability in Zabbix Server (versions <6.0.32rc1, <6.4.17rc1, <7.0.1rc1). The exploit consists of a single Python script ('zabbix_privesc.py') and a README.md with detailed usage instructions. The exploit works by authenticating to the Zabbix API as a low-privileged user, leveraging a SQL injection in the 'user.get' API method to extract the admin API authentication token, and then using this token to create a malicious item that executes a reverse shell payload. The attacker must provide the target Zabbix API URL, valid user credentials, and a listener IP/port for the reverse shell. The script automates the entire attack chain, including token extraction, host enumeration, and payload delivery. The main network endpoints involved are the Zabbix API endpoint (typically at '/zabbix/api_jsonrpc.php') and the attacker's TCP listener for the reverse shell. The exploit is operational and provides a shell as the 'zabbix' user on the target system.
This repository contains a working exploit for CVE-2024-42327, a critical SQL injection vulnerability in Zabbix Server. The exploit is implemented in Python (exploit.py) and is accompanied by a detailed README.md explaining the vulnerability and attack steps. The exploit works by authenticating to the Zabbix API (requiring valid credentials), then performing a time-based SQL injection to extract the admin session ID from the database. With this session ID, it queries for host and interface IDs, and finally creates a malicious item that triggers a reverse shell payload, granting the attacker remote shell access to the Zabbix server. The exploit is multi-threaded to speed up the extraction process. The main endpoints involved are the Zabbix API (user-supplied URL) and the attacker's listener (lhost/lport). The payload is a bash reverse shell. The code is operational and can be used for real-world exploitation of unpatched Zabbix servers.
This repository contains a single Python proof-of-concept exploit script (poc.py) targeting Zabbix servers vulnerable to SQL injection in the CUser.php component. The script requires valid Zabbix user credentials and the target's IP address. It exploits a SQL injection vulnerability via the Zabbix API endpoint (/zabbix/api_jsonrpc.php) to enumerate user accounts and passwords, retrieve an admin session token, and ultimately execute arbitrary commands on the server. The script can deliver a base64-encoded bash reverse shell or a custom command, leveraging the Zabbix API's script.create and script.execute methods. The exploit is operational, providing both credential enumeration and remote code execution capabilities. The code is self-contained, with all logic in a single file, and is intended for use against Zabbix instances with exposed and vulnerable API endpoints.
This repository provides a Python proof-of-concept exploit for CVE-2024-42327, an authenticated SQL injection vulnerability in Zabbix (versions 6.0.0–6.0.31, 6.4.0–6.4.16, and 7.0.0). The exploit targets the 'user.get' API method, specifically abusing the 'selectRole' parameter to inject arbitrary SQL queries. The main script, 'CVE-2024-42327_Zabbix_SQLI.py', allows an attacker with valid Zabbix API credentials to: - Leak user credentials (usernames and password hashes) from the database - Leak session tokens for further API access - Execute custom SQL queries via the injection point The script requires the target Zabbix URL, a username, and a password. It constructs and sends crafted JSON-RPC requests to the Zabbix API endpoint ('api_jsonrpc.php'), exploiting the vulnerable parameter. The README.md provides detailed usage instructions, affected versions, and technical background on the vulnerability. No detection-only scripts or fake payloads are present; the code is a functional exploit. The only code file is the exploit script itself, written in Python.
This repository contains a working exploit and proof-of-concept for CVE-2024-42327 (Zabbix ZBX-25623), a time-based blind SQL injection vulnerability in the Zabbix monitoring platform (versions 6.0.0-6.0.31, 6.4.0-6.4.16, 7.0.0). The exploit targets the Zabbix API endpoint (/api_jsonrpc.php) and leverages the 'user.get' method with a crafted 'selectRole' parameter to inject SQL. The provided Python script authenticates as a non-admin user with API access, tests for the vulnerability using a time-based SQLi payload, and, if successful, extracts user table data and enumerates database tables. The repository consists of a detailed README.md explaining the vulnerability, affected versions, and usage instructions, and a single Python exploit script (cve-2024-42327-PoC.py) implementing the attack. The exploit is operational, providing both detection and data extraction capabilities.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-42327, a time-based blind SQL injection vulnerability in Zabbix version 6.0.31. The main exploit script, 'cve-2024-42327.py', is written in Python and automates the process of authenticating to the Zabbix API as a non-admin user and sending a specially crafted JSON-RPC request to the '/api_jsonrpc.php' endpoint. The payload leverages the 'selectRole' parameter in the 'user.get' API method to inject a SQL statement that triggers a 5-second delay if the target is vulnerable. The script measures the response time to determine if the SQL injection was successful. The repository also includes a 'README.md' with detailed vulnerability information and exploitation steps, and an 'infrastructure/compose.yaml' file for setting up a local Zabbix environment using Docker Compose. The exploit is a functional PoC and does not provide post-exploitation capabilities beyond vulnerability detection.
This repository contains an operational exploit for CVE-2024-42327, a vulnerability in Zabbix (ZBX-25623) that allows unauthorized access to sensitive user information via the JSON-RPC API. The main exploit script, 'cve-2024-42327.py', is a Python program that authenticates to the Zabbix API using provided credentials, then iterates over user IDs 1 to 40, sending crafted 'user.get' requests to extract user details including usernames, names, surnames, user IDs, and password hashes. The script requires the target Zabbix server's API endpoint URL and valid user credentials. The README provides usage instructions, and the included 'zabbix.cast' file is an asciinema recording demonstrating the exploit in action. The exploit is network-based, targeting the Zabbix JSON-RPC API endpoint (e.g., http://192.168.201.128/api_jsonrpc.php), and is capable of disclosing sensitive user data from vulnerable Zabbix instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability identified as CVE-2024-42327 affecting Zabbix's user.get functionality, referenced here in the context of adding version detection.
Critical Zabbix vulnerability in the CUser.get function caused by insufficient user input validation, enabling an authenticated remote attacker with API access to exploit SQL injection for privilege escalation and full system compromise.
A critical SQL injection vulnerability in the Zabbix frontend API (CUser class addRelatedObjects called from CUser.get) that can allow privilege escalation and further impact; exploitable by non-admin users with default roles or any role with API access.
A critical SQL injection vulnerability in Zabbix that can be exploited via the user.get API endpoint by non-admin users with API access, potentially allowing privilege escalation and takeover of vulnerable Zabbix servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.