CVE-2019-7327: XSS
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php) because proper filtration is omitted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7327?
CVE-2019-7327 is a vulnerability that allows an attacker to execute HTML or JavaScript code via a reflected cross-site scripting (XSS) attack in ZoneMinder through version 1.32.3.
How severe is CVE-2019-7327?
CVE-2019-7327 has a severity rating of 6.1, which is considered medium.
How does CVE-2019-7327 work?
CVE-2019-7327 works by exploiting a vulnerability in the 'scale' parameter value in the view frame (frame.php) of ZoneMinder, allowing the execution of malicious HTML or JavaScript code.
Is there a fix available for CVE-2019-7327?
Yes, updating ZoneMinder to version 1.32.4 or later will fix the CVE-2019-7327 vulnerability.
Where can I find more information about CVE-2019-7327?
You can find more information about CVE-2019-7327 on the GitHub page for ZoneMinder's issue #2447.