CVE-2019-7330: XSS
Published Feb 4, 2019
·Updated
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'show' parameter value in the view frame (frame.php) because proper filtration is omitted.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2019-7330.
2
What is the severity level of CVE-2019-7330?
The severity level of CVE-2019-7330 is medium.
3
What is the CWE ID associated with CVE-2019-7330?
The CWE ID associated with CVE-2019-7330 is CWE-79.
4
How does the vulnerability affect ZoneMinder?
The vulnerability affects ZoneMinder versions up to and including 1.32.3.
5
Is there a known fix for CVE-2019-7330?
Yes, upgrading to a version higher than 1.32.3 resolves the vulnerability.