A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
{
"versions": [
{
"introduced": "7.0.0"
},
{
"last_affected": "7.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.8-rc1"
}
]
}