CVE-2019-7341: XSS
Published Feb 4, 2019
·Updated
Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[LinkedMonitors]' parameter value in the view monitor (monitor.php) because proper filtration is omitted.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2019-7341.
2
What is the severity rating of CVE-2019-7341?
CVE-2019-7341 has a severity rating of medium.
3
What software version is affected by CVE-2019-7341?
CVE-2019-7341 affects ZoneMinder versions up to 1.32.3.
4
How does the vulnerability in CVE-2019-7341 work?
CVE-2019-7341 is a reflected cross-site scripting (XSS) vulnerability that allows an attacker to execute HTML or JavaScript code by manipulating the 'newMonitor[LinkedMonitors]' parameter in the view monitor page (monitor.php) of ZoneMinder.
5
Is there a fix available for CVE-2019-7341?
Yes, upgrading ZoneMinder to a version beyond 1.32.3 will fix the vulnerability.