CVE-2024-51482
CRITICAL 9.9EPSS 35.0%
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
- CVSS v3.1
- 9.9 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS
- 34.98% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- critical · CWE-89
- Published
- 2024-10-31
- Updated
- 2024-11-08
Proof-of-concept exploits (7)
- BwithE/CVE-2024-514821★ · 2025-10-05
- 0xDaeras/CVE-2024-51482-POC
- BridgerAlderson/CVE-2024-51482
- Ravi-lk/CVE-2024-51482-ZoneMinder-v1.37.-1.37.64-SQL-Injection-POC
- c0gnit00/CVE-2024-51482
- lnn0v4/sqli-hunter-CVE-2024-51482-PoC
- plur1bu5/CVE-2024-51482-PoC