Unrated severityNVD Advisory· Published Feb 25, 2023· Updated Mar 10, 2025
ZoneMinder contains SQL injection via malicious Jason Web Token
CVE-2023-26032
Description
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web token. The Username field of the JWT token was trusted when performing an SQL query to load the user. If an attacker could determine the HASH key used by ZoneMinder, they could generate a malicious JWT token and use it to execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.
Affected products
1- Range: < 1.36.33
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/ZoneMinder/zoneminder/security/advisories/GHSA-6c72-q9mw-mwx9mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.