PT-2023-20439 · Unknown+2 · Zoneminder+2

Manfred Paul

·

Published

2023-02-25

·

Updated

2023-11-30

·

CVE-2023-26037

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to 1.36.33 ZoneMinder versions prior to 1.37.33
Description The issue is related to an SQL Injection in ZoneMinder, a free, open source Closed-circuit television software application for Linux. The minTime and maxTime request parameters are not properly validated, allowing them to be used to execute arbitrary SQL.
Recommendations For versions prior to 1.36.33, update to version 1.36.33 or later. For versions prior to 1.37.33, update to version 1.37.33 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1939
ALT-PU-2023-2056
ALT-PU-2023-4121
ALT-PU-2023-7284
CVE-2023-26037
GHSA-65JP-2HJ3-3733

Affected Products

Alt Linux
Debian
Zoneminder