First published: Mon Feb 04 2019(Updated: )
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoneminder Zoneminder | <=1.32.3 | |
<=1.32.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-7325.
The severity of CVE-2019-7325 is medium with a CVSS score of 6.1.
The software version affected by CVE-2019-7325 is ZoneMinder 1.32.3.
The CWE ID associated with CVE-2019-7325 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
To fix CVE-2019-7325, apply the latest security patch or upgrade to a version of ZoneMinder that is not affected by this vulnerability.