漏洞描述 Zabbix SIA Zabbix是拉脱维亚Zabbix SIA公司的一套开源的监控系统。Zabbix 4.4及之前版本中的zabbix.php?action=dashboard.view&dashboardid=1存在授权问题漏洞。该漏洞源于网络系统或产品中缺少身份验证措施或身份验证强度不足。
相关漏洞推荐 Zabbix /api_jsonrpc.php SQL 注入漏洞(CVE-2024-36465) POC CVE-2024-22120: Zabbix Server - Time-Based Blind SQL injection POC CVE-2016-10134: Zabbix - SQL Injection POC CVE-2019-17382: Zabbix <=4.4 - Authentication Bypass POC CVE-2022-23131: Zabbix - SAML SSO Authentication Bypass POC CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC CVE-2016-10134: Zabbix SQL Injection Vulnerability POC CVE-2022-23131: Zabbix - SAML SSO Authentication Bypass POC CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC zabbix-default-password: Zabbix Default Password POC zabbix-authentication-bypass: Zabbix authentication Bypass