First published: Mon Jan 28 2019(Updated: )
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to the index.php?view=controlcaps URI.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | <=1.32.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6992 is classified as medium due to its potential for stored XSS attacks.
To fix CVE-2019-6992, upgrade ZoneMinder to version 1.32.4 or later.
CVE-2019-6992 allows attackers to execute arbitrary HTML and JavaScript code in the browser of an affected user.
Users running ZoneMinder versions up to and including 1.32.3 are affected by CVE-2019-6992.
Symptoms of exploitation may include unexpected scripts being executed in the user's browser when interacting with vulnerable fields.