PT-2026-102386 · Unknown · Zoneminder
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZoneMinder versions 1.37.0 through 1.37.x
Description
Authenticated users with Events view permission can read arbitrary files due to improper validation of the
path parameter before it is passed to the output file function. This path traversal issue allows access to sensitive information, such as configuration files containing database credentials.Recommendations
Update ZoneMinder to version 1.38.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoneminder