在 ZoneMinder 1.37.0 至 1.38.0(不含 1.38.0)版本中,文件查看功能存在路径遍历漏洞,允许已认证用户读取任意文件。该漏洞源于对传入 函数的 参数未进行充分验证,使得拥有“事件查看”权限的攻击者能够访问敏感文件,例如包含数据库凭据的配置文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZoneMinder | zoneminder | 1.37.0 ~ 1.38.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102296 | 6.5 MEDIUM | ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response |
| CVE-2026-102297 | 4.3 MEDIUM | ZoneMinder before 1.38.4 Incorrect Authorization in frames API index |
No comments yet