ZoneMinder Security Update Advisory (CVE-2024-51482)

Overview

 

An update has been released to address vulnerabilities in ZoneMinder. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-51482

  • ZoneMinder versions: ~ 1.37.64 (inclusive)

 

 

Resolved Vulnerabilities

 

Boolean-based SQL injection vulnerability in the web/ajax/event.php function (CVE-2024-51482)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-51482

  • ZoneMinder version: 1.37.65
     

 

Referenced Sites

 

[1] CVE-2024-51482 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-51482

[2] Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64

https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-qm8h-3xvf-m7j3

[3] zoneminder/commit

https://github.com/ZoneMinder/zoneminder/commit/9e7d31841ed9678a7dd06869037686fc9925e59f