ZoneMinder contains SQL Injection via report_event_audit
CVE-2023-26037
8.9HIGH
What is CVE-2023-26037?
ZoneMinder, an open-source CCTV software for Linux, is susceptible to SQL injection due to insufficient validation of the minTime and maxTime parameters in user requests. This vulnerability allows potential attackers to execute arbitrary SQL commands, compromising the integrity of the database and sensitive data. Users are urged to upgrade to ZoneMinder versions 1.36.33, 1.37.33 or later to mitigate this risk. For detailed remediation steps, visit the official advisory.
Affected Version(s)
zoneminder < 1.36.33 < 1.36.33
zoneminder >= 1.37.0, < 1.37.33 < 1.37.0, 1.37.33
References
CVSS V3.1
Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved