First published: Mon Aug 12 2024(Updated: )
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | <1.36.34 | |
ZoneMinder | >=1.37.00<1.37.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43360 is classified as a significant security risk due to its potential for SQL injection attacks.
To fix CVE-2024-43360, update ZoneMinder to version 1.36.34 or later, or to version 1.37.61 or later.
CVE-2024-43360 affects ZoneMinder versions prior to 1.36.34 and between versions 1.37.00 and 1.37.61.
CVE-2024-43360 is a time-based SQL Injection vulnerability that could allow attackers to manipulate database queries.
It is not safe to continue using an affected version of ZoneMinder as it exposes your system to SQL injection risks.