CVE-2023-31493

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.
Configurations

No configuration.

History

16 Oct 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6
CWE CWE-94

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) RCE (Remote Code Execution) existe en ZoneMinder hasta la versión 1.36.33, ya que un atacante puede crear un nuevo archivo de registro .php en la carpeta de idioma, mientras ejecuta un payload manipulado y escalar privilegios que permitan la ejecución de cualquier comando en el sistema remoto.

15 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 15:15

Updated : 2024-10-16 19:35


NVD link : CVE-2023-31493

Mitre link : CVE-2023-31493

CVE.ORG link : CVE-2023-31493


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')