CVE-2023-26032

CVSS v3 Score
8.1
High

Vulnerability Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web token. The Username field of the JWT token was trusted when performing an SQL query to load the user. If an attacker could determine the HASH key used by ZoneMinder, they could generate a malicious JWT token and use it to execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.

CVSS:8.1(High)

SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.

CWE-892015
CVSS:8.1(High)

SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.

CWE-892015
CVSS:8.1(High)

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CWE-892015
CVSS:8.1(High)

Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbit...

CWE-892015
CVSS:8.1(High)

cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).

CWE-892016
CVSS:8.1(High)

SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to system...

CWE-892016