PT-2023-20441 · Unknown+2 · Zoneminder+2

Aymen Borgi

·

Publicado

2023-02-25

·

Atualizado

2023-11-30

·

CVE-2023-26039

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to 1.36.33 ZoneMinder versions prior to 1.37.33
Description The issue is an OS Command Injection via the daemonControl() function in the /web/api/app/Controller/HostController.php file. Any authenticated user can construct an API command to execute any shell command as the web user.
Recommendations For versions prior to 1.36.33, update to version 1.36.33 or later. For versions prior to 1.37.33, update to version 1.37.33 or later. As a temporary workaround, consider restricting access to the daemonControl() function in the /web/api/app/Controller/HostController.php file until a patch is applied.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1939
ALT-PU-2023-2056
ALT-PU-2023-4121
ALT-PU-2023-7284
CVE-2023-26039
GHSA-44Q8-H2PW-CC9G

Produtos afetados

Alt Linux
Debian
Zoneminder