CVE-2024-51482: Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
Published Oct 31, 2024
·Updated
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37. <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.37.64
Event History
Oct 31, 2024
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51482?
CVE-2024-51482 has a high severity due to its potential for boolean-based SQL injection, which can lead to unauthorized data access.
2
How do I fix CVE-2024-51482?
To fix CVE-2024-51482, upgrade your ZoneMinder installation to version 1.37.65 or later.
3
Which versions of ZoneMinder are affected by CVE-2024-51482?
ZoneMinder versions 1.37.* up to and including 1.37.64 are affected by CVE-2024-51482.
4
What type of vulnerability is CVE-2024-51482?
CVE-2024-51482 is classified as a boolean-based SQL injection vulnerability.
5
Where can I find more information about CVE-2024-51482?
More information about CVE-2024-51482 can be found in the ZoneMinder security advisories and relevant GitHub commits.