The Zabbix server can execute commands for configured scripts. After executing a command, an audit entry is added to the "Audit Log". Due to the "clientip" field not being sanitized, it is possible to inject SQL into "clientip" and exploit a time-based blind SQL injection vulnerability.
id: CVE-2024-22120
info:
name: Zabbix Server - Time-Based Blind SQL injection
author: CodeStuff
...