CVE Tools

HTB CCTV. Раскрываем админскую панель motionEye и повышаем привилегии

Хакер (xakep.ru)By RalfHacker

PoC publicZoneMindermotionEye

Our summary

A recent article details how attackers can exploit the SQL injection vulnerability CVE-2024-51482 in ZoneMinder versions 1.37.* through 1.37.64 to extract user hashes and escalate privileges to root access. The flaw exists in the web/ajax/event.php component and allows unauthorized database manipulation using boolean-based logic. This vulnerability was demonstrated on a Hack The Box training machine running ZoneMinder 1.37.63, where default credentials were used to gain initial access before exploiting the SQLi path. Users are advised to update to version 1.37.65 or later to mitigate this risk.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store