Description
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46370 | ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34. |
References
History
Tue, 13 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoneminder
Zoneminder zoneminder |
|
| CPEs | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zoneminder
Zoneminder zoneminder |
|
| Metrics |
ssvc
|
Mon, 12 Aug 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34. | |
| Title | ZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-13T17:34:56.389Z
Reserved: 2023-09-04T16:31:48.224Z
Link: CVE-2023-41884
Updated: 2024-08-13T17:34:47.325Z
Status : Analyzed
Published: 2024-08-12T20:15:07.917
Modified: 2024-09-13T15:08:19.280
Link: CVE-2023-41884
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD