Skip to main content

CVE-2023-26037

8.9
HIGHCVSS v3.1 Base Score
0.71%
LOW RiskEPSS (73rd percentile)

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and could be used execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.

Published: 2/25/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.9HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

EPSS Score (Exploitation Probability)

0.71%LOW Exploitation Risk
73rd percentile

This vulnerability has a 0.71% probability of being exploited in the next 30 days, ranking higher than 73% of all scored CVEs.

Related Vulnerabilities