Unrated severityNVD Advisory· Published Feb 25, 2023· Updated Mar 10, 2025
ZoneMinder contains Local File Inclusion vulnerability
CVE-2023-26036
Description
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via /web/index.php. By controlling $view, any local file ending in .php can be executed. This is supposed to be mitigated by calling detaintPath, however dentaintPath does not properly sandbox the path. This can be exploited by constructing paths like "..././", which get replaced by "../". This issue is patched in versions 1.36.33 and 1.37.33.
Affected products
1- Range: < 1.36.33
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/ZoneMinder/zoneminder/security/advisories/GHSA-h5m9-6jjc-cgmwmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.