CVE-2023-41884: ZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php
Published Aug 12, 2024
·Updated
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
Affected Software
1 affected component
ZoneMinder Zoneminder<1.36.34
Remediation
Event History
Aug 12, 2024
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-41884?
CVE-2023-41884 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2023-41884?
To fix CVE-2023-41884, upgrade ZoneMinder to version 1.36.34 or later.
3
What type of vulnerability is CVE-2023-41884?
CVE-2023-41884 is an SQL injection vulnerability affecting ZoneMinder.
4
Which versions of ZoneMinder are affected by CVE-2023-41884?
All versions of ZoneMinder prior to 1.36.34 are affected by CVE-2023-41884.
5
Where is the vulnerable code in CVE-2023-41884 located?
The vulnerable code for CVE-2023-41884 is located in WWW/AJAX/watch.php at line 51.