CVE-2019-7325: XSS
Published Feb 4, 2019
·Updated
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $REQUEST['PHPSELF'], without applying any proper filtration.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-7325.
2
What is the severity of CVE-2019-7325?
The severity of CVE-2019-7325 is medium with a CVSS score of 6.1.
3
Which software version is affected by CVE-2019-7325?
The software version affected by CVE-2019-7325 is ZoneMinder 1.32.3.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2019-7325?
The CWE ID associated with CVE-2019-7325 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
How can I fix CVE-2019-7325?
To fix CVE-2019-7325, apply the latest security patch or upgrade to a version of ZoneMinder that is not affected by this vulnerability.