Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-26039
HistoryFeb 25, 2023 - 2:15 a.m.

Command injection

2023-02-2502:15:00
PRIOn knowledge base
www.prio-n.com
4
zoneminder
command injection
cctv software
linux
os command injection
daemoncontrol
hostcontroller
shell command

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

Related for PRION:CVE-2023-26039