8.9 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
0.001 Low
EPSS
Percentile
46.6%
ZoneMinder is a free, open source Closed-circuit television software
application for Linux which supports IP, USB and Analog cameras. Versions
prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web
token. The Username field of the JWT token was trusted when performing an
SQL query to load the user. If an attacker could determine the HASH key
used by ZoneMinder, they could generate a malicious JWT token and use it to
execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 20.04 | noarch | zoneminder | < any | UNKNOWN |
ubuntu | 22.04 | noarch | zoneminder | < any | UNKNOWN |
ubuntu | 23.10 | noarch | zoneminder | < any | UNKNOWN |
ubuntu | 24.04 | noarch | zoneminder | < any | UNKNOWN |
ubuntu | 16.04 | noarch | zoneminder | < any | UNKNOWN |