CVE-2019-7333: XSS
Published Feb 4, 2019
·Updated
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Exportfile' parameter value in the view download (download.php) because proper filtration is omitted.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability in ZoneMinder?
The vulnerability ID for this XSS vulnerability in ZoneMinder is CVE-2019-7333.
2
What is the severity of CVE-2019-7333?
The severity of CVE-2019-7333 is medium, with a CVSS score of 6.1.
3
How does the vulnerability CVE-2019-7333 work?
The vulnerability CVE-2019-7333 allows an attacker to execute HTML or JavaScript code by exploiting a reflected Cross-Site Scripting (XSS) vulnerability in ZoneMinder through a vulnerable 'Exportfile' parameter value.
4
Which version of ZoneMinder is affected by CVE-2019-7333?
ZoneMinder version 1.32.3 is affected by CVE-2019-7333.
5
Is there a patch or fix available for CVE-2019-7333?
Yes, a fix for CVE-2019-7333 is available in ZoneMinder version 1.32.4 or later.