ZoneMinder vulnerable to OS Command injection in daemonControl() API
CVE-2023-26039
What is CVE-2023-26039?
An OS Command Injection vulnerability exists in ZoneMinder, a popular open-source software for managing closed-circuit television systems, affecting versions prior to 1.36.33 and 1.37.33. This flaw allows authenticated users to construct API commands that can execute arbitrary shell commands as the web user, posing significant security risks. The vulnerability is addressed in the latest software releases, emphasizing the importance of updating to safeguard against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zoneminder < 1.36.33 < 1.36.33
zoneminder >= 1.37.0, < 1.37.33 < 1.37.0, 1.37.33
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
