Vulnerabilities · InfosecFeed Brief
Zoneminder
Vulnerabilities
What you need to know
Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 CVSS Vendor Equipment Vulnerabilities v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…
Source transparency
Read the original report at CISA Alerts ↗
This is an InfosecFeed curated brief based on reporting from CISA Alerts. InfosecFeed does not claim ownership of the original reporting.