CVE-2024-43360: ZoneMinder Time-based SQL Injection
Published Aug 12, 2024
·Updated
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
Affected Software
2 affected components
ZoneMinder Zoneminder<1.36.34
ZoneMinder Zoneminder>=1.37.00<1.37.61
Remediation
Event History
Aug 12, 2024
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43360?
CVE-2024-43360 is classified as a significant security risk due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-43360?
To fix CVE-2024-43360, update ZoneMinder to version 1.36.34 or later, or to version 1.37.61 or later.
3
Which versions of ZoneMinder are affected by CVE-2024-43360?
CVE-2024-43360 affects ZoneMinder versions prior to 1.36.34 and between versions 1.37.00 and 1.37.61.
4
What type of vulnerability is CVE-2024-43360?
CVE-2024-43360 is a time-based SQL Injection vulnerability that could allow attackers to manipulate database queries.
5
Is it safe to continue using an affected version of ZoneMinder for now?
It is not safe to continue using an affected version of ZoneMinder as it exposes your system to SQL injection risks.