CVE-2019-8428: SQL Injection
Published Feb 18, 2019
·Updated
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
Affected Software
1 affected component
ZoneMinder Zoneminder<1.32.3
Event History
Feb 18, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-8428.
2
What is the severity level of CVE-2019-8428?
The severity level of CVE-2019-8428 is critical.
3
How does ZoneMinder before 1.32.3 get affected by CVE-2019-8428?
ZoneMinder before 1.32.3 is affected by CVE-2019-8428 through the skins/classic/views/control.php groupSql parameter, which allows SQL Injection.
4
How can I fix the vulnerability in ZoneMinder?
To fix the vulnerability in ZoneMinder, you must upgrade to version 1.32.3 or later.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2019-8428?
The Common Weakness Enumeration (CWE) ID associated with CVE-2019-8428 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).