CVE-2019-8423: SQL Injection
Published Feb 18, 2019
·Updated
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 18, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for ZoneMinder?
The vulnerability ID for ZoneMinder is CVE-2019-8423.
2
What is the severity of CVE-2019-8423?
The severity of CVE-2019-8423 is critical with a CVSS score of 9.8.
3
How does the SQL Injection occur in ZoneMinder?
The SQL Injection occurs via the filter[Query][terms][0][cnj] parameter in skins/classic/views/events.php in ZoneMinder before version 1.32.3.
4
What is the affected software version of ZoneMinder?
ZoneMinder version 1.32.3 and earlier are affected by this vulnerability.
5
Is there any fix available for CVE-2019-8423?
Yes, upgrading to ZoneMinder version 1.32.4 or later will fix the vulnerability.