PT-2022-24874 · Unknown+2 · Zoneminder+2

Published

2022-10-07

·

Updated

2023-11-30

·

CVE-2022-39291

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions ZoneMinder (affected versions not specified)
Description The issue allows users with "View" system permissions to inject new data into the logs stored by ZoneMinder through an HTTP POST request to the "/zm/index.php" endpoint. This could affect database performance and/or consume all storage resources due to uncontrolled submission.
Recommendations Upgrade to a newer version to resolve the issue. At the moment, there is no information about specific versions that contain a fix for this vulnerability, so upgrading to the latest available version is advised.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2858
ALT-PU-2022-2978
ALT-PU-2023-7284
CVE-2022-39291
GHSA-CFCX-V52X-JH74

Affected Products

Alt Linux
Debian
Zoneminder