Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39632
HistoryMar 10, 2023 - 4:24 p.m.

SQL Injection

2023-03-1016:24:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
sql injection
zoneminder
vulnerability
filter parameter
data access
authentication bypass
remote code execution

8.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.6%

zoneminder is vulnerable to SQL Injection attacks. The SQL Injection vulnerability is present in the filter[Query][terms][0][attr] query string parameter of the /zm/index.php endpoint, allowing unauthorized data access, authentication bypass, and remote code execution.

8.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.6%