RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.
2024-10-15T15:15:12.393
2025-05-27T13:55:33.557
Analyzed
CVSSv3.1: 6.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zoneminder | zoneminder | ≤ 1.36.33 | Yes |