First published: Thu Jan 24 2019(Updated: )
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | =1.32.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6777 has a medium severity rating due to the potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2019-6777, update ZoneMinder to version 1.32.4 or later where the vulnerability is patched.
CVE-2019-6777 affects ZoneMinder by allowing an attacker to exploit reflected XSS via a crafted URL.
If you are using ZoneMinder v1.32.3, it is recommended that you upgrade to a patched version immediately to mitigate the risk.
Yes, there are known exploits for CVE-2019-6777 that take advantage of the reflected XSS vulnerability in the application.