← back
CVE-2023-41884highCWE-89

ZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
ZoneMinder · zoneminder