CVE-2019-6990: XSS
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6990?
CVE-2019-6990 is a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2019-6990?
To fix CVE-2019-6990, you should update ZoneMinder to a version higher than 1.32.3, where the vulnerability has been addressed.
What type of vulnerability is CVE-2019-6990?
CVE-2019-6990 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary HTML or JavaScript code.
Which versions of ZoneMinder are affected by CVE-2019-6990?
CVE-2019-6990 affects all versions of ZoneMinder up to and including 1.32.3.
Can CVE-2019-6990 be exploited remotely?
Yes, CVE-2019-6990 can be exploited remotely by an attacker if they can manipulate the Zone NAME in the vulnerable field.