First published: Mon Aug 12 2024(Updated: )
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | <1.36.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41884 is classified as a high severity SQL injection vulnerability.
To fix CVE-2023-41884, upgrade ZoneMinder to version 1.36.34 or later.
CVE-2023-41884 is an SQL injection vulnerability affecting ZoneMinder.
All versions of ZoneMinder prior to 1.36.34 are affected by CVE-2023-41884.
The vulnerable code for CVE-2023-41884 is located in WWW/AJAX/watch.php at line 51.