Vulnerability Description
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoneminder | Zoneminder | <= 1.36.33 |
Related Weaknesses (CWE)
References
- http://zoneminder.comProduct
- https://medium.com/%40dk50u1/rce-remote-code-execution-in-zoneminder-up-to-1-36-ExploitThird Party Advisory
FAQ
What is CVE-2023-31493?
CVE-2023-31493 is a vulnerability with a CVSS score of 6.6 (MEDIUM). RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing ex...
How severe is CVE-2023-31493?
CVE-2023-31493 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31493?
Check the references section above for vendor advisories and patch information. Affected products include: Zoneminder Zoneminder.