CVE-2022-29806
Ubuntu Security Notice USN-5889-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
ZoneMinder antes de la versión 1.36.13 permite la ejecución remota de código a través de un lenguaje no válido. La capacidad de crear un archivo de registro de depuración en una ruta arbitraria contribuye a la explotabilidad
It was discovered that ZoneMinder was not properly sanitizing URL parameters for certain views. An attacker could possibly use this issue to perform a cross-site scripting attack. This issue was only fixed in Ubuntu 16.04 ESM. It was discovered that ZoneMinder was not properly sanitizing stored user input later printed to the user in certain views. An attacker could possibly use this issue to perform a cross-site scripting attack. This issue was only fixed in Ubuntu 16.04 ESM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-26 CVE Reserved
- 2022-04-26 CVE Published
- 2022-05-05 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/ZoneMinder/zoneminder/releases/tag/1.36.13 | Release Notes |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/166980 | 2022-05-05 | |
http://packetstormsecurity.com/files/166980/ZoneMinder-Language-Settings-Remote-Code-Execution.html | 2024-08-03 | |
https://krastanoel.com/cve/2022-29806 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/ZoneMinder/zoneminder/commit/9fee64b62fbdff5bf5ece1d617f1f53c7b1967cb | 2022-05-06 |
URL | Date | SRC |
---|---|---|
https://forums.zoneminder.com/viewtopic.php?t=31638 | 2022-05-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zoneminder Search vendor "Zoneminder" | Zoneminder Search vendor "Zoneminder" for product "Zoneminder" | < 1.36.13 Search vendor "Zoneminder" for product "Zoneminder" and version " < 1.36.13" | - |
Affected
|