CVE-2025-27236 - User information disclosure via api_jsonrpc.php on method user.get with param search
CVE ID : CVE-2025-27236
Published : Oct. 3, 2025, 11:28 a.m. | 31 minutes ago
Description : A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 3, 2025, 11:28 a.m. | 31 minutes ago
Description : A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...