CVE-2022-39289

CRITICAL

ZoneMinder < 1.36.27 - Missing Authorization for Database Log Manipulation

Title source: llm
STIX 2.1

Description

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.

Scores

CVSS v3 9.1
EPSS 0.0075
EPSS Percentile 50.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-200 CWE-287 CWE-862
Status published
Products (1)
zoneminder/zoneminder < 1.36.27
Published Oct 07, 2022
Tracked Since Feb 18, 2026