S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 15, 2024

CVE-2024-43360 Scanner

CVE-2024-43360 scanner - SQL Injection vulnerability in ZoneMinder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-43360
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
zoneminderby ZoneMinder
< 1.36.34
zoneminderby zoneminder
\u003c.1.36.34
Updated Sep 10, 2026View on NVD →
Detail

ZoneMinder is an open-source software widely used for closed-circuit television (CCTV) systems. Security teams, surveillance operators, and IT administrators rely on ZoneMinder for effective monitoring and video management. It is compatible with a range of hardware, making it adaptable to various surveillance setups. ZoneMinder helps organizations manage and control multiple video streams, allowing centralized monitoring. Users deploy this software to enhance security and surveillance capabilities within private, public, and corporate environments.

This vulnerability in ZoneMinder allows unauthorized users to execute SQL injection attacks. It affects specific versions, 1.36.34 and 1.37.61, posing risks to data integrity. Through this attack, malicious actors can manipulate database queries, potentially gaining unauthorized access to sensitive information. Successful exploitation could lead to severe data breaches or other security compromises within the affected system.

The vulnerability exploits an SQL injection point within the ZoneMinder software's database querying process. Specifically, the flaw exists in the endpoint located at /zm/index.php, where unsanitized input parameters enable time-based SQL injections. Attackers may manipulate the sort parameter to control conditional delays, exploiting the software's failure to correctly sanitize and validate inputs. The issue is triggered by a SQL condition that, when manipulated, causes a conditional delay in the server's response, confirming the presence of the vulnerability. This injection vulnerability compromises data security by exposing backend data to potential extraction or modification.

When exploited, this SQL injection vulnerability can allow attackers to extract, alter, or delete sensitive information from the ZoneMinder database. Unauthorized access may result in data breaches, loss of confidentiality, and alteration of stored information. Attackers may also gain privileges within the system, compromising the integrity and availability of the surveillance data. In extreme cases, the vulnerability can enable attackers to disable or disrupt surveillance operations.

S4E provides proactive security management for your critical digital assets. By using the platform, you can safeguard against various vulnerabilities, from configuration issues to SQL injection attacks, enhancing your digital security profile. With extensive, detailed vulnerability assessments, S4E enables you to monitor, prioritize, and mitigate risks efficiently. Becoming a member allows access to continuous monitoring, timely alerts, and actionable reports to stay ahead of potential threats. Strengthen your security posture and protect your infrastructure today by joining the S4E community.

References:

Solution Advice
  • Apply the latest ZoneMinder software update to version 1.36.34 or 1.37.61.
  • Restrict access to the affected endpoints through network-level controls.
  • Implement input validation to prevent malicious injections.
  • Regularly monitor and audit database queries to identify potential anomalies.
  • Review and harden access control policies on database and application layers.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-43360 scanner - SQL Injection vulnerability in ZoneMinder | S4E