User-controlled Parameter Vulnerability in ZoneMinder by ZoneMinder
CVE-2018-1000833
9.8CRITICAL
What is CVE-2018-1000833?
The ZoneMinder software version 1.32.2 and earlier is susceptible to a vulnerability that arises from insufficient validation of user-controlled parameters. This flaw could potentially allow attackers to access confidential information, trigger denial of service, exploit server-side request forgery (SSRF), or even carry out remote code execution. Proper mitigation measures should be undertaken to secure the affected versions of this crucial video surveillance software.