Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39633
HistoryMar 10, 2023 - 4:24 p.m.

SQL Injection

2023-03-1016:24:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
zoneminder
sql injection
jwt
hash key

8.6 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.6%

zoneminder is vulnerable to SQL Injection attacks. An attacker could use a malicious JWT token to execute SQL queries, as the Username field of the JWT token was trusted. If the HASH key used by ZoneMinder was determined, the attacker could generate a malicious JWT token and use it to execute arbitrary SQL queries.

8.6 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.6%