Impact
ZoneMinder versions 1.37.0 up to 1.37.x contain a path traversal vulnerability in the files view. This flaw is a Path Traversal (CWE-22) vulnerability. The path parameter is not validated before being passed to output_file, allowing authenticated users with Events view permission to read arbitrary files on the host. Attackers could therefore access configuration files that contain database credentials or other sensitive data, compromising confidentiality.
Affected Systems
Vulnerable versions include any 1.37.x release before the 1.38.0 update, affecting the ZoneMinder surveillance software deployed on network cameras and media servers. The affected product is the ZoneMinder package from the ZoneMinder vendor. The vulnerability affects all installations that enable the files view functionality, regardless of other configuration settings.
Risk and Exploitability
The CVSS score is 7.1, indicating a high-impact vulnerability, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access with Events view permission, which is typically granted to users who can see recorded footage. By manipulating the path argument, they can traverse directories and read files outside the intended directory, making exploitation straightforward for users who already have legitimate access. The risk is especially high in environments where ZoneMinder reads configuration files that include database passwords, as the vulnerability enables credential theft.
OpenCVE Enrichment