Loading market data...
← Back to CVE feed

CVE-2024-58386

MEDIUM CVSS 6.5 View on NVD ↗

Description

ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Sep 28, 2026 22:17 UTC Modified: Sep 28, 2026 22:17 UTC