Incorrect authorization in ZoneMinder - #VU153359
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive event data.
The vulnerability exists due to incorrect authorization in the AJAX dispatcher in web/index.php and the raw branch of web/ajax/stats.php when handling AJAX requests with view=none. A remote attacker can send a request containing view=none, request=stats, raw=1, and a matching event/frame ID pair to disclose sensitive event data.
Exploitation requires ZM_OPT_USE_AUTH=1, ZM_RECORD_EVENT_STATS=1, and a corresponding Stats row. Event and frame IDs are sequential integers.