CVE-2024-51482

Published Oct 31, 2024

Last updated 12 days ago

Overview

Description
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-89

Social media

Hype score
Not currently trending
  1. 🚨Alert🚨CVE-2024-51482: A 10/10 Severity Vulnerability Exposes ZoneMinder’s SQL Databases 📊 5K+ Services are found vulnerable. 👇Query SHODAN:http.favicon.hash:-1218152116 FOFA: app="ZoneMinder" https://t.co/lsFyuJQuGg

    @Yetmez1526

    8 Nov 2024

    17 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🚨Alert🚨CVE-2024-51482: A 10/10 Severity Vulnerability Exposes ZoneMinder’s SQL Databases 📊 5K+ Services are found on https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/fEwqbfBeC9 👇Query HUNTER:/product.name="ZoneMinder" SHODAN: http.favicon.hash:-1218152116 FOFA:… ht

    @HunterMapping

    8 Nov 2024

    5177 Impressions

    32 Retweets

    74 Likes

    28 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️⚠️ CVE-2024-51482: A 10/10 Severity Vulnerability Exposes ZoneMinder’s SQL Databases 🎯3k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/ViplGE1keR FOFA Query:app="ZoneMinder" 🔖Refer: https://t.co/uLpHZWFA7B https://t.co/1eEsyFgVm2

    @fofabot

    5 Nov 2024

    2150 Impressions

    17 Retweets

    39 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨🚨CVE-2024-51482 (CVSS: 10) : Boolean-based SQL Injection in ZoneMinder ⚠️The issue arises from a Boolean-based SQL injection vulnerability within the web/ajax/event.php function. A lack of input validation for the tagId parameter allows attackers to manipulate the SQL query… h

    @zoomeye_team

    5 Nov 2024

    740 Impressions

    4 Retweets

    7 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  5. ZoneMinder's CVE-2024-51482: A 10/10 Severity Vulnerability Exposes #SQL Databases Learn about CVE-2024-51482, a critical security vulnerability in #ZoneMinder that could compromise data confidentiality and system integrity https://t.co/Qg0eiC0Nke

    @the_yellow_fall

    5 Nov 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-51482 Boolean-Based SQL Injection in ZoneMinder v1.37 - Critical Fix Released ZoneMinder is an open-source CCTV software. In versions up to 1.37.64, there's a vulnerability related to boolean-based SQL I... https://t.co/0xTXbEF2Vd

    @VulmonFeeds

    31 Oct 2024

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2024-51482: CRITICAL] ZoneMinder v1.37.* &lt;= 1.37.64 had a SQL Injection vulnerability in web/ajax/event.php. Update to version 1.37.64 to secure your system from this cyber threat. #cybersecurity#cybersecurity,#vulnerability https://t.co/h65VhEyYQP https://t.co/Wkr5yNYtMu

    @CveFindCom

    31 Oct 2024

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2024-51482 ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* &lt;= 1.37.64 is vulnerable to boolean-based SQL Injection in functi… https://t.co/LT7Pkjn7zW

    @CVEnew

    31 Oct 2024

    369 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes