Vulnerability Details CVE-2019-8428
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-8428
-
cpe:2.3:a:zoneminder:zoneminder:-
-
cpe:2.3:a:zoneminder:zoneminder:1.25
-
cpe:2.3:a:zoneminder:zoneminder:1.26
-
cpe:2.3:a:zoneminder:zoneminder:1.26.0
-
cpe:2.3:a:zoneminder:zoneminder:1.26.1
-
cpe:2.3:a:zoneminder:zoneminder:1.26.2
-
cpe:2.3:a:zoneminder:zoneminder:1.26.3
-
cpe:2.3:a:zoneminder:zoneminder:1.26.4
-
cpe:2.3:a:zoneminder:zoneminder:1.26.5
-
cpe:2.3:a:zoneminder:zoneminder:1.27.0
-
cpe:2.3:a:zoneminder:zoneminder:1.28.0
-
cpe:2.3:a:zoneminder:zoneminder:1.28.1
-
cpe:2.3:a:zoneminder:zoneminder:1.29.0
-
cpe:2.3:a:zoneminder:zoneminder:1.30.0
-
cpe:2.3:a:zoneminder:zoneminder:1.30.1
-
cpe:2.3:a:zoneminder:zoneminder:1.30.2
-
cpe:2.3:a:zoneminder:zoneminder:1.30.3
-
cpe:2.3:a:zoneminder:zoneminder:1.30.4
-
cpe:2.3:a:zoneminder:zoneminder:1.30.5
-
cpe:2.3:a:zoneminder:zoneminder:1.32.0
-
cpe:2.3:a:zoneminder:zoneminder:1.32.1
-
cpe:2.3:a:zoneminder:zoneminder:1.32.2