Path Traversal Vulnerability in ZoneMinder by ZoneMinder
CVE-2024-58386
7.1HIGH
What is CVE-2024-58386?
A path traversal vulnerability exists in ZoneMinder versions 1.37.0 up to but not including 1.38.0. This flaw allows authenticated users with permission to view events to read arbitrary files on the server, including sensitive configuration files containing database credentials, due to improper validation of the path parameter before it is passed to the output_file function. Attackers could exploit this vulnerability to gain unauthorized access to crucial information, posing a significant risk to security.
Affected Version(s)
zoneminder 1.37.0 < 1.38.0
