CVE-2023-26038
published 2023-02-25CVE-2023-26038: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.51%
39.9th percentile
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via web/ajax/modal.php, where an arbitrary php file path can be passed in the request and loaded. This issue is patched in versions 1.36.33 and 1.37.33.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.36.33+dfsg1-1 (bookworm) | zoneminder 1.36.33+dfsg1-1 (bookworm) |
| zoneminder | zoneminder | < 1.36.33 | 1.36.33 |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | >= 0 < 1.36.33+dfsg1-1 | 1.36.33+dfsg1-1 |
| zoneminder | zoneminder | >= 0 < 1.36.33+dfsg1-1 | 1.36.33+dfsg1-1 |
| zoneminder | zoneminder | >= 0 < 1.36.33+dfsg1-1 | 1.36.33+dfsg1-1 |
| zoneminder | zoneminder | >= 1.37.00 < 1.37.33 | 1.37.33 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian5.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-26038: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras
osv·2023-02-25·CVSS 6.5
CVE-2023-26038 [MEDIUM] CVE-2023-26038: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via web/ajax/modal.php, where an arbitrary php file path can be passed in the request and loaded. This issue is patched in versions 1.36.33 and 1.37.33.
Debian
CVE-2023-26038: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application...
vendor_debian·2023·CVSS 5.4
CVE-2023-26038 [MEDIUM] CVE-2023-26038: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application...
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via web/ajax/modal.php, where an arbitrary php file path can be passed in the request and loaded. This issue is patched in versions 1.36.33 and 1.37.33.
Scope: local
bookworm: resolved (fixed in 1.36.33+dfsg1-1)
bullseye: open
forky: resolved (fixed in 1.36.33+dfsg1-1)
sid: resolved (fixed in 1.36.33+dfsg1-1)
trixie: resolved (fixed in 1.36.33+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-25
Published