CVE-2023-26037
Published: 25 February 2023
Summary
CVE-2023-26037 is a high-severity SQL Injection (CWE-89) vulnerability in Zoneminder Zoneminder. Its CVSS base score is 8.9 (High).
Operationally, ranked in the top 27.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-29923
Vulnerability details
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and…
more
could be used execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.