CVE-2025-27240
published 2025-09-12CVE-2025-27240: A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
PriorityP351high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.19%
64.5th percentile
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.5+dfsg-1 (forky) | zabbix 1:7.0.5+dfsg-1 (forky) |
| zabbix | zabbix | >= 0 < 1:7.0.5+dfsg-1 | 1:7.0.5+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:7.0.5+dfsg-1 | 1:7.0.5+dfsg-1 |
| zabbix | zabbix | >= 6.0.0 < 6.0.34 | 6.0.34 |
| zabbix | zabbix | 6.0.0 – 6.0.33 | — |
| zabbix | zabbix | >= 6.4.0 < 6.4.19 | 6.4.19 |
| zabbix | zabbix | 6.4.0 – 6.4.18 | — |
| zabbix | zabbix | >= 7.0.0 < 7.0.4 | 7.0.4 |
| zabbix | zabbix | 7.0.0 – 7.0.3 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.5HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-27240: zabbix - A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts b...
vendor_debian·2025·CVSS 7.5
CVE-2025-27240 [HIGH] CVE-2025-27240: zabbix - A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts b...
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:7.0.5+dfsg-1)
sid: resolved (fixed in 1:7.0.5+dfsg-1)
trixie: resolved (fixed in 1:7.0.5+dfsg-1)
OSV
CVE-2025-27240: A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field
osv·2025-09-12·CVSS 7.5
CVE-2025-27240 [HIGH] CVE-2025-27240: A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
GHSA
GHSA-pvp6-r25h-5wh3: A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field
ghsa_unreviewed·2025-09-12
CVE-2025-27240 [HIGH] CWE-89 GHSA-pvp6-r25h-5wh3: A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-12
Published