ZoneMinder contains SQL Injection via report_event_audit
CVE-2023-26037

8.9HIGH

Key Information:

Vendor

Zoneminder

Vendor
CVE Published:
25 February 2023

What is CVE-2023-26037?

ZoneMinder, an open-source CCTV software for Linux, is susceptible to SQL injection due to insufficient validation of the minTime and maxTime parameters in user requests. This vulnerability allows potential attackers to execute arbitrary SQL commands, compromising the integrity of the database and sensitive data. Users are urged to upgrade to ZoneMinder versions 1.36.33, 1.37.33 or later to mitigate this risk. For detailed remediation steps, visit the official advisory.

Affected Version(s)

zoneminder < 1.36.33 < 1.36.33

zoneminder >= 1.37.0, < 1.37.33 < 1.37.0, 1.37.33

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-26037 : ZoneMinder contains SQL Injection via report_event_audit