CVE-2021-46088 Information
Jun 07, 2022
cve
Description
Zabbix 4.0 LTS 4.2 4.4 and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the \Zabbix Admin\ role is able to run custom shell script on the application server in the context of the application user.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/paalbra/zabbix-zbxsec-7
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: