ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.
History

Mon, 10 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-10T21:05:12.912Z

Reserved: 2023-02-17T22:44:03.149Z

Link: CVE-2023-26039

cve-icon Vulnrichment

Updated: 2024-08-02T11:39:06.485Z

cve-icon NVD

Status : Modified

Published: 2023-02-25T02:15:13.957

Modified: 2024-11-21T07:50:38.360

Link: CVE-2023-26039

cve-icon Redhat

No data.