zoneminder/web/api/app
Isaac Connor b036408a5b Fix RCE vulnerability via API config edit privilege escalation
Add RBAC checks to ConfigsController edit() and delete() requiring
System=Edit permission, matching the pattern used by other controllers.
Harden System/Readonly column checks with !empty() to handle missing
columns gracefully. Fix command injection in Event.php by using
ZM_PATH_FFMPEG constant with escapeshellarg() instead of hardcoded
unsanitized ffmpeg call. Add is_executable() validation at all exec()
sites using ZM_PATH_FFMPEG as defense-in-depth against poisoned config
values.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 13:51:30 -05:00
..
Config feat: add User Roles feature for reusable permission templates 2026-01-29 13:34:27 -05:00
Console further merges from cakephp 2.10.8 2018-03-21 13:09:55 -04:00
Controller Fix RCE vulnerability via API config edit privilege escalation 2026-02-26 13:51:30 -05:00
Model fix: correct App::uses package path in CameraModel 2026-02-15 15:38:08 -05:00
Plugin Put back to 3.0 2023-02-01 14:34:05 -05:00
View Add Tags support to API 2023-11-03 13:33:28 -04:00
vendor Merged Angular UI branch API to master 2015-06-11 02:58:58 +00:00
webroot Upgrade cakephp to 2.10.24 2021-03-31 12:11:12 -04:00
index.php Upgrade cakephp to 2.10.24 2021-03-31 12:11:12 -04:00