Description
|
|
Two vulnerabilities have been reported in Zabbix, which can be exploited by malicious users to conduct SQL injection attacks.
Input passed via the "periods" and "itemid" GET parameter to chart_bar.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerabilities are reported in versions prior to 1.8.22, 2.0.14, and 2.2.8.
|