ZoneMinder Security Update Advisory (CVE-2024-51482)
Overview
An update has been released to address vulnerabilities in ZoneMinder. Users of the affected versions are advised to update to the latest version.
Affected Products
CVE-2024-51482
- ZoneMinder versions: ~ 1.37.64 (inclusive)
Resolved Vulnerabilities
Boolean-based SQL injection vulnerability in the web/ajax/event.php function (CVE-2024-51482)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-51482
- ZoneMinder version: 1.37.65
Referenced Sites
[1] CVE-2024-51482 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-51482
[2] Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-qm8h-3xvf-m7j3
[3] zoneminder/commit
https://github.com/ZoneMinder/zoneminder/commit/9e7d31841ed9678a7dd06869037686fc9925e59f