SQL Injection Vulnerability in ZoneMinder's WWW/AJAX/watch.php
CVE-2023-41884
6.5MEDIUM
What is CVE-2023-41884?
A vulnerability exists in ZoneMinder, an open-source closed-circuit television software, that makes it susceptible to SQL injection attacks. The issue arises from improperly sanitized inputs in the SQL queries, particularly noted in the WWW/AJAX/watch.php file. This flaw allows potential attackers to manipulate SQL queries, leading to unauthorized data access and manipulation. The vulnerability has been addressed in version 1.36.34 of the software, highlighting the importance of timely updates and security practices for users of ZoneMinder.
Affected Version(s)
zoneminder < 1.36.34