ZoneMinder 在 1.38.4 版本之前存在漏洞:在 FramesController 的 index 端点中,未能正确应用基于单个监控摄像头的访问限制。拥有“查看事件”权限的已认证用户可以通过调用 frames API 来列出其无权访问的监控摄像头的帧记录,从而在监控摄像头之间泄露事件和帧元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZoneMinder | zoneminder | 0 ~ 1.38.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58386 | 6.5 MEDIUM | ZoneMinder 1.37.x Path Traversal via files view |
| CVE-2026-102296 | 6.5 MEDIUM | ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response |
No comments yet