CVE-2023-31493: Code Injection
Published Oct 15, 2024
·Updated
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.
Affected Software
2 affected components
ZoneMinder Zoneminder<=1.36.33
ZoneMinder Zoneminder<=1.36.33
Event History
Oct 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-31493?
CVE-2023-31493 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2023-31493?
To fix CVE-2023-31493, upgrade ZoneMinder to version 1.36.34 or later.
3
What are the potential impacts of CVE-2023-31493?
The potential impacts of CVE-2023-31493 include unauthorized access and execution of arbitrary commands on the affected system.
4
Who is affected by CVE-2023-31493?
CVE-2023-31493 affects all users of ZoneMinder versions up to and including 1.36.33.
5
What is the nature of the vulnerability in CVE-2023-31493?
CVE-2023-31493 is a remote code execution vulnerability that allows attackers to create a .php log file to execute commands.