CVE Tools
Back to feed
PoC public ZoneMinder privilege-escalation motionEye Hack The Box web-app

HTB CCTV. Раскрываем админскую панель motionEye и повышаем привилегии

Хакер (xakep.ru)·By RalfHacker··2 min read
CVE Tools coverage

A recent article details how attackers can exploit the SQL injection vulnerability CVE-2024-51482 in ZoneMinder versions 1.37.* through 1.37.64 to extract user hashes and escalate privileges to root access. The flaw exists in the web/ajax/event.php component and allows unauthorized database manipulation using boolean-based logic. This vulnerability was demonstrated on a Hack The Box training machine running ZoneMinder 1.37.63, where default credentials were used to gain initial access before exploiting the SQLi path. Users are advised to update to version 1.37.65 or later to mitigate this risk.