Zabbix 3.0.3, vulnerable to CVE-2016-10134: the toggle_ids array of latest.php and the profileIdx2 parameter of jsrpc.php reach SQL queries unescaped, so the guest account (or no session for jsrpc.php) runs error-based SQL injection.
Not startedDockercommit db62463x86_64 · aarch64Secret
Exploit CVE-2016-10134 to inject SQL into Zabbix and read the flag from the database.
The brief for this lab lives in its repository.