CVE-2019-7332: XSS
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'eid' (aka Event ID) parameter value in the view download (download.php) because proper filtration is omitted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7332?
CVE-2019-7332 is a vulnerability that allows an attacker to execute HTML or JavaScript code via a vulnerable 'eid' parameter value in ZoneMinder through version 1.32.3.
How does the Reflected Cross Site Scripting (XSS) vulnerability in CVE-2019-7332 work?
The vulnerability in CVE-2019-7332 allows an attacker to execute HTML or JavaScript code by exploiting a lack of proper input filtration in the 'eid' parameter of ZoneMinder's view download feature.
What is the severity of CVE-2019-7332?
CVE-2019-7332 has a severity rating of medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2019-7332?
CVE-2019-7332 affects versions up to and including 1.32.3 of the ZoneMinder software.
Is there a fix available for CVE-2019-7332?
Yes, a fix for the CVE-2019-7332 vulnerability is available through the updates provided by ZoneMinder.