Vulnerabilities · InfosecFeed Brief

Zoneminder

Vulnerabilities

What you need to know

Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 CVSS Vendor Equipment Vulnerabilities v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…

Source transparency

This is an InfosecFeed curated brief based on reporting from CISA Alerts. InfosecFeed does not claim ownership of the original reporting.

Read the original report at CISA Alerts ↗