8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function. Event field values (specifically Name and Cause) are stored safely via parameterized queries but are later retrieved and concatenated directly into SQL WHERE clauses without escaping. An authenticated user with Events edit and view permissions can exploit this to execute arbitrary SQL queries.
AI Analysis
Second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function
Basic Information
ID
CVE-2026-27470
Source
GitHub_M
Published
Feb 21, 2026 at 08:05
Affected Product
Vendor
ZoneMinder
Product
zoneminder
Version
< 1.36.38
Affected Versions
ZoneMinder zoneminder < 1.36.38
ZoneMinder zoneminder >= 1.37.61, < 1.38.1
ZoneMinder zoneminder >= 1.37.61, < 1.38.1
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
ZoneMinder
Product
ZoneMinder
Version
1.36.37 and below, 1.37.61 through 1.38.0