An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access.
References
Link | Resource |
---|---|
https://support.zabbix.com/browse/ZBX-25614 |
Configurations
No configuration.
History
27 Nov 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-27 07:15
Updated : 2024-11-27 07:15
NVD link : CVE-2024-36467
Mitre link : CVE-2024-36467
CVE.ORG link : CVE-2024-36467
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization