CVE-2023-26032
Discription

ZoneMinder is a free, open source Closed-circuit television software
application for Linux which supports IP, USB and Analog cameras. Versions
prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web
token. The Username field of the JWT token was trusted when performing an
SQL query to load the user. If an attacker could determine the HASH key
used by ZoneMinder, they could generate a malicious JWT token and use it to
execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.Read More

Back to Main

Subscribe for the latest news: