PT-2023-20440 · Unknown+2 · Zoneminder+2

Manfred Paul

·

Published

2023-02-25

·

Updated

2023-11-30

·

CVE-2023-26038

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to 1.36.33 ZoneMinder versions prior to 1.37.33
Description The issue concerns a Local File Inclusion vulnerability via the "web/ajax/modal.php" endpoint, where an arbitrary php file path can be passed in the request and loaded.
Recommendations For versions prior to 1.36.33, update to version 1.36.33 or later. For versions prior to 1.37.33, update to version 1.37.33 or later.

Exploit

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1939
ALT-PU-2023-2056
ALT-PU-2023-4121
ALT-PU-2023-7284
CVE-2023-26038
GHSA-WRX3-R8C4-R24W

Affected Products

Alt Linux
Debian
Zoneminder