First published: Mon Feb 04 2019(Updated: )
Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'group' as it insecurely prints the 'Group Name' value on the web page without applying any proper filtration.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoneminder Zoneminder | <=1.32.3 | |
<=1.32.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-7338.
The severity of CVE-2019-7338 is medium with a score of 6.1.
The affected software for CVE-2019-7338 is ZoneMinder version 1.32.3.
The CWE ID for CVE-2019-7338 is CWE-79.
An attacker can exploit CVE-2019-7338 by executing HTML or JavaScript code in the 'group' view of ZoneMinder.