PT-2022-24874 · Unknown+2 · Zoneminder+2

CVE-2022-39291

·

Published

2022-10-07

·

Updated

2023-11-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions ZoneMinder (affected versions not specified)
Description The issue allows users with "View" system permissions to inject new data into the logs stored by ZoneMinder through an HTTP POST request to the "/zm/index.php" endpoint. This could affect database performance and/or consume all storage resources due to uncontrolled submission.
Recommendations Upgrade to a newer version to resolve the issue. At the moment, there is no information about specific versions that contain a fix for this vulnerability, so upgrading to the latest available version is advised.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2858
ALT-PU-2022-2978
ALT-PU-2023-7284
CVE-2022-39291
GHSA-CFCX-V52X-JH74

Affected Products

Alt Linux
Debian
Zoneminder