CVE-2023-26038

MEDIUM

ZoneMinder <1.36.33-1.37.33 - Local File Inclusion

Title source: llm
STIX 2.1

Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via web/ajax/modal.php, where an arbitrary php file path can be passed in the request and loaded. This issue is patched in versions 1.36.33 and 1.37.33.

Scores

CVSS v3 5.4
EPSS 0.0025
EPSS Percentile 48.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-426
Status published
Products (1)
zoneminder/zoneminder < 1.36.33
Published Feb 25, 2023
Tracked Since Feb 18, 2026