Critical severity9.1NVD Advisory· Published Oct 7, 2022· Updated Jun 17, 2026
CVE-2022-39289
CVE-2022-39289
Description
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*range: <=1.36.27
- (no CPE)
- (no CPE)range: < 1.36.27
Patches
Vulnerability mechanics
References
2- github.com/ZoneMinder/zoneminder/commit/34ffd92bf123070cab6c83ad4cfe6297dd0ed0b4nvdPatchThird Party Advisory
- github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mpcx-3gvh-9488nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.