CVE-2019-13072: XSS
Published Jun 30, 2019
·Updated
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
Affected Software
1 affected component
ZoneMinder Zoneminder=1.32.3
Remediation
Patch Available
Event History
Jun 30, 2019
CVE Published
via MITRE·01:03 AM
Data Sourced
via MITRE·01:03 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-13072.
2
What is the severity of CVE-2019-13072?
The severity of CVE-2019-13072 is medium.
3
What is the affected software version of CVE-2019-13072?
The affected software version of CVE-2019-13072 is ZoneMinder 1.32.3.
4
How does CVE-2019-13072 affect users?
CVE-2019-13072 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to the Filters page (Name field) in ZoneMinder 1.32.3.
5
Are there any known fixes for CVE-2019-13072?
At the moment, there are no known fixes for CVE-2019-13072. It is recommended to update to a newer version of ZoneMinder when one becomes available.