CVE-2024-36465 | Zabbix up to 7.0.7/7.2.1 API CApiService.php groupBy sql injection
A vulnerability classified as critical has been found in Zabbix up to 7.0.7/7.2.1. This affects an unknown part of the file include/classes/api/CApiService.php of the component API. The manipulation of the argument groupBy leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-36465. It is possible to initiate the attack remotely. There is no exploit available.