CVE-2023-41884: Zoneminder

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.

Affected products

  • Zoneminder Zoneminder: before 1.36.34 (fixed in 1.36.34)

Published 2024-08-12. Last modified 2026-06-17.