Feed/CVE-2024-51482
CVE-2024-51482CRITICALCVSS 9.9

CVE-2024-51482

Published Oct 31, 2024·Updated Jun 17, 2026

NVD Description

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

Public Exploits & PoCs11 found

PoC: CVE-2024-51482

CVE-2025-51482 POC, Dump Credentials From zm.Users

PoC: htb-cctv

HackTheBox — CCTV (Easy/Linux) | CVE-2024-51482 + SqlMap+ SSH Key + Root

PoC: CVE-2024-51482-POC

Time-based blind SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.

PoC: CCTV-MACHINE

A black box penetration test on HackTheBox's CCTV machine achieving full root compromise via four vulnerabilities: default credentials, SQL injection (CVE-2024-51482), password hash cracking, and Remote Code Execution in motionEye (CVE-2025-60787)

PoC: CVE-2024-51482-ZoneMinder-CCTV-HTB-Reliable-EXP

Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and improves reliability, through it is time-consuming.

PoC: sqli-hunter-CVE-2024-51482-PoC

Scripts en Python para la explotación de CVE-2024-51482 (SQLi en ZoneMinder) — HTB CCTV

PoC: CVE-2024-51482-ZoneMinder-v1.37.-1.37.64-SQL-Injection-POC

ZoneMinder Time-Based SQL Injection (CVE-2024-51482) Exploit POC

PoC: CVE-2024-51482

ZenoMinder Blind SQL Injection PoC

PoC: CVE-2024-51482-PoC

Authenticated time-based blind SQL injection exploit for ZoneMinder CVE-2024-51482 (v1.37.* <= 1.37.64)

PoC: CVE-2024-51482-Multi-Stage-Surveillance-System-Exploit

MinderZone 1.37.* ≤ 1.37.63

PoC: CVE-2024-51482

CVE-2024-51482 poc

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free