Back

CVE-2016-10134

CRITICAL

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

Published: Feb 17, 2017 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (5)

Vendor Product Version
zabbix zabbix *
zabbix zabbix 3.0.0
zabbix zabbix 3.0.1
zabbix zabbix 3.0.2
zabbix zabbix 3.0.3

GitHub Security Advisory GHSA-q33m-pmcq-844x

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 83.41%

Top 0% most likely to be exploited

Threat Score 74.2 / 100

Data Sources

NVD EPSS GitHub