关键漏洞信息 CVE ID: CVE-2025-27240 CVSS Score: 7.3 (High) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SI:N Affected Components: Server Summary: Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host Description: A Zabbix administrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. Known Attack Vectors: The attacker needs to be a Zabbix administrator and also needs access to a host that is later auto-removed. Affected and Fix Versions: - Affected: 6.0.0 - 6.0.33 → Fixed: 6.0.34 - Affected: 6.4.0 - 6.4.18 → Fixed: 6.0.19 - Affected: 7.0.0 - 7.0.3 → Fixed: 7.0.4 Mitigation: Update the affected components to their respective fixed versions. Workarounds: Disable any Autoregistration actions that remove hosts. Acknowledgements: Zabbix wants to thank Grzegorz Muszyński (szerszen199) for submitting this report on the HackerOne bug bounty platform.