CVE-2023-25825
- EPSS 0.71%
- Veröffentlicht 25.02.2023 01:15:56
- Zuletzt bearbeitet 21.11.2024 07:50:16
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs...
CVE-2023-26032
- EPSS 0.62%
- Veröffentlicht 25.02.2023 01:15:56
- Zuletzt bearbeitet 21.11.2024 07:50:37
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web token. The Username field of the...
CVE-2023-26034
- EPSS 1.58%
- Veröffentlicht 25.02.2023 01:15:56
- Zuletzt bearbeitet 21.11.2024 07:50:37
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulne...
CVE-2022-30769
- EPSS 0.48%
- Veröffentlicht 15.11.2022 22:15:11
- Zuletzt bearbeitet 30.04.2025 17:15:49
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.
CVE-2022-30768
- EPSS 0.57%
- Veröffentlicht 15.11.2022 22:15:11
- Zuletzt bearbeitet 30.04.2025 17:15:49
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: ...
CVE-2022-39291
- EPSS 5.39%
- Veröffentlicht 07.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:58
ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. ...
CVE-2022-39290
- EPSS 5.81%
- Veröffentlicht 07.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:58
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing...
CVE-2022-39289
- EPSS 0.81%
- Veröffentlicht 07.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:57
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privil...
CVE-2022-39285
- EPSS 3.94%
- Veröffentlicht 07.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:57
ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This then allows a malicious user to pro...
CVE-2022-29806
- EPSS 67.13%
- Veröffentlicht 26.04.2022 04:15:42
- Zuletzt bearbeitet 21.11.2024 06:59:43
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.