PT-2022-24874 · Unknown+2 · Zoneminder+2
Published
2022-10-07
·
Updated
2023-11-30
·
CVE-2022-39291
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ZoneMinder (affected versions not specified)
Description
The issue allows users with "View" system permissions to inject new data into the logs stored by ZoneMinder through an HTTP POST request to the "/zm/index.php" endpoint. This could affect database performance and/or consume all storage resources due to uncontrolled submission.
Recommendations
Upgrade to a newer version to resolve the issue.
At the moment, there is no information about specific versions that contain a fix for this vulnerability, so upgrading to the latest available version is advised.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Zoneminder