CVE-2022-39291 is a log injection vulnerability affecting ZoneMinder, an open-source CCTV software. Authenticated users with "View" system permissions can inject arbitrary data into logs via an un-rate-limited HTTP POST request to the /zm/index.php endpoint. This medium severity vulnerability (CVSS 5.4) has a low attack complexity and could lead to denial of service by consuming database and storage resources. While not actively exploited in the wild, an ExploitDB entry exists, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.36.27CPE matchmatch criteria | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | ||
> 1.37.0, < 1.37.24CPE matchmatch criteria | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.