PT-2024-13007 · Unknown+2 · Zoneminder+2

Pl4Tyz

·

Published

2024-08-12

·

Updated

2024-09-18

·

CVE-2023-41884

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZoneMinder versions prior to 1.36.34
Description The issue is related to a SQL injection vulnerability in the ZoneMinder application. Specifically, the watch.php file takes a few parameters in an SQL query without proper sanitization, making it vulnerable to SQL injection attacks.
Recommendations For versions prior to 1.36.34, update to version 1.36.34 to resolve the issue. As a temporary workaround, consider restricting access to the watch.php file until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12804
CVE-2023-41884
GHSA-2QP3-FWPV-MC96

Affected Products

Alt Linux
Debian
Zoneminder