CVE-2019-8424: SQL Injection
Published Feb 18, 2019
·Updated
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
Affected Software
1 affected component
ZoneMinder Zoneminder<1.32.3
Event History
Feb 18, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8424.
2
What is the severity of CVE-2019-8424?
The severity of CVE-2019-8424 is classified as critical with a severity value of 9.8.
3
How can this vulnerability be exploited?
This vulnerability can be exploited through a SQL Injection attack via the ajax/status.php sort parameter in ZoneMinder before version 1.32.3.
4
Which software versions are affected by CVE-2019-8424?
ZoneMinder versions up to, but excluding, 1.32.3 are affected by CVE-2019-8424.
5
Is there a fix available for CVE-2019-8424?
Yes, the fix for CVE-2019-8424 is to update ZoneMinder to version 1.32.3 or later.