CVE-2019-6777: XSS
Published Jan 24, 2019
·Updated
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
Affected Software
1 affected component
ZoneMinder Zoneminder=1.32.3
Remediation
Event History
Jan 24, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6777?
CVE-2019-6777 has a medium severity rating due to the potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-6777?
To fix CVE-2019-6777, update ZoneMinder to version 1.32.4 or later where the vulnerability is patched.
3
How does CVE-2019-6777 affect ZoneMinder?
CVE-2019-6777 affects ZoneMinder by allowing an attacker to exploit reflected XSS via a crafted URL.
4
What should I do if I am using ZoneMinder v1.32.3 after discovering CVE-2019-6777?
If you are using ZoneMinder v1.32.3, it is recommended that you upgrade to a patched version immediately to mitigate the risk.
5
Is there a known exploit for CVE-2019-6777?
Yes, there are known exploits for CVE-2019-6777 that take advantage of the reflected XSS vulnerability in the application.