Time-Based SQL Injection Vulnerability in ZoneMinder by ZoneMinder Team
CVE-2024-43360
9.8CRITICAL
What is CVE-2024-43360?
ZoneMinder, a widely used open-source closed-circuit television software application, is susceptible to a time-based SQL Injection vulnerability. This vulnerability can allow attackers to manipulate SQL queries through crafted input, resulting in unauthorized data access or manipulation. Users are advised to upgrade to versions 1.36.34 or 1.37.61, where this issue has been addressed. It is crucial for ZoneMinder users to apply these patches to safeguard their systems against potential exploitation.