ZoneMinder是一套开源的视频监控软件系统。该系统支持IP、USB和模拟摄像机等。 ZoneMinder 1.36.26及之前版本、1.37.23及之前版本存在安全漏洞,该漏洞源于,经过身份验证的用户可以通过修改提供给 Zoneminder Web 应用程序的请求来绕过 CSRF 密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZoneMinder | zoneminder | < 1.36.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39289 | 9.1 CRITICAL | Database log access in ZoneMinder |
| CVE-2022-39285 | 7.6 HIGH | Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder |
| CVE-2022-39291 | 5.4 MEDIUM | Denial of service through logs in zoneminder |
No comments yet