Path Traversal Vulnerability in ZoneMinder by ZoneMinder
CVE-2024-58386

7.1HIGH

Key Information:

Vendor

Zoneminder

Vendor
CVE Published:
28 September 2026

What is CVE-2024-58386?

A path traversal vulnerability exists in ZoneMinder versions 1.37.0 up to but not including 1.38.0. This flaw allows authenticated users with permission to view events to read arbitrary files on the server, including sensitive configuration files containing database credentials, due to improper validation of the path parameter before it is passed to the output_file function. Attackers could exploit this vulnerability to gain unauthorized access to crucial information, posing a significant risk to security.

Affected Version(s)

zoneminder 1.37.0 < 1.38.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

leediay153
.