HomeZoneminderCVE-2023-26032

CVE-2023-26032

HIGH
8.9CVSS
Published: 2023-02-25
Updated: 2024-11-21
AI Analysis

Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web token. The Username field of the JWT token was trusted when performing an SQL query to load the user. If an attacker could determine the HASH key used by ZoneMinder, they could generate a malicious JWT token and use it to execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Attack Vector
network
Complexity
high
Privileges
none
User Action
none
Scope
changed
Confidentiality
high
Integrity
high
Availability
low
Weaknesses
CWE-89CWE-89

Metadata

Primary Vendor
ZONEMINDER
Published
2/25/2023
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

zoneminder : zoneminderzoneminder : zoneminder

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-26032 | HIGH Severity | CVEDatabase.com | CVEDatabase.com