SQL Injection Vulnerability in ZoneMinder by ZoneMinder Developers
CVE-2019-8424
9.8CRITICAL
What is CVE-2019-8424?
The vulnerability in ZoneMinder prior to version 1.32.3 enables an attacker to execute arbitrary SQL queries through a manipulation of the ajax/status.php sort parameter. This flaw could lead to unauthorized access to sensitive data and database manipulation, posing a serious risk to the integrity and confidentiality of the affected systems.