CVE-2024-51482
CVE-2024-51482 affects ZoneMinder, a CCTV software, exposing it to SQL Injection. This vulnerability allows attackers to manipulate SQL queries, potentially granting unauthorized access to sensitive data. ZoneMinder versions 1.37.* up to 1.37.64 are vulnerable; the fix is available in version 1.37.65. Although the CVSS score is 0, indicating a seemingly low immediate impact, the boolean-based SQL Injection flaw allows attackers to infer information about the database structure and data. Given that the vulnerability has a 'In The Wild' tag, this suggests active exploitation attempts, requiring vigilant monitoring. The SVRS score of 30 indicates a moderate level of risk. Organizations using vulnerable versions of ZoneMinder should prioritize upgrading to version 1.37.65 to mitigate potential data breaches and unauthorized system access.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.