Code Injection in ZoneMinder - CVE-2023-26035
Published: March 1, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in snapshots. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2023-26035
Links to Public Exploits and PoC-codes
- Exploit #10665 - ZoneMinder Snapshots < 1.37.33 - Unauthenticated RCE (October 25, 2024)
- Exploit #9548 - zoneminder-snapshots-rce-poc (This is a script written in Python that allows the exploitation of the Zoneminder's security flaw described in CVE-2023-26035. ) (February 13, 2024)
- Exploit #9466 - zoneminder_CVE-2023-26035 (Exploit for CVE-2023-26035 affecting ZoneMinder < 1.36.33 and < 1.37.33) (December 27, 2023)
- Exploit #9454 - CVE-2023-26035 (Unauthenticated RCE in ZoneMinder Snapshots - Poc Exploit) (December 21, 2023)
- Exploit #9439 - CVE-2023-26035 (POC script for CVE-2023-26035 (zoneminder 1.36.32) ) (December 19, 2023)
- Exploit #9410 - ZoneMinder Snapshots Command Injection (November 10, 2023)