First published: Thu Oct 31 2024(Updated: )
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | <=1.37.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51482 has a high severity due to its potential for boolean-based SQL injection, which can lead to unauthorized data access.
To fix CVE-2024-51482, upgrade your ZoneMinder installation to version 1.37.65 or later.
ZoneMinder versions 1.37.* up to and including 1.37.64 are affected by CVE-2024-51482.
CVE-2024-51482 is classified as a boolean-based SQL injection vulnerability.
More information about CVE-2024-51482 can be found in the ZoneMinder security advisories and relevant GitHub commits.