ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials. | |
| Title | ZoneMinder 1.37.x Path Traversal via files view | |
| First Time appeared |
Zoneminder
Zoneminder zoneminder |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zoneminder
Zoneminder zoneminder |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:28:06.645Z
Reserved: 2026-09-28T21:24:45.481Z
Link: CVE-2024-58386
No data.
Status : Received
Published: 2026-09-28T22:17:29.893
Modified: 2026-09-28T22:17:29.893
Link: CVE-2024-58386
No data.
OpenCVE Enrichment
No data.
Weaknesses