First published: Mon Feb 04 2019(Updated: )
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'eid' (aka Event ID) parameter value in the view download (download.php) because proper filtration is omitted.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoneminder Zoneminder | <=1.32.3 | |
<=1.32.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7332 is a vulnerability that allows an attacker to execute HTML or JavaScript code via a vulnerable 'eid' parameter value in ZoneMinder through version 1.32.3.
The vulnerability in CVE-2019-7332 allows an attacker to execute HTML or JavaScript code by exploiting a lack of proper input filtration in the 'eid' parameter of ZoneMinder's view download feature.
CVE-2019-7332 has a severity rating of medium with a CVSS score of 6.1.
CVE-2019-7332 affects versions up to and including 1.32.3 of the ZoneMinder software.
Yes, a fix for the CVE-2019-7332 vulnerability is available through the updates provided by ZoneMinder.