CVE-2019-7342: XSS
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filter[AutoExecuteCmd]' parameter value in the view filter (filter.php) because proper filtration is omitted.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-7342.
What is the title of the vulnerability?
The title of the vulnerability is 'POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filter[AutoExecuteCmd]' parameter value in the view filter (filter.php) because proper filtration is omitted.'
What is the severity of CVE-2019-7342?
The severity of CVE-2019-7342 is medium with a severity value of 6.1.
What software versions are affected by CVE-2019-7342?
ZoneMinder versions up to and including 1.32.3 are affected by CVE-2019-7342.
How can an attacker exploit CVE-2019-7342?
An attacker can exploit CVE-2019-7342 by executing HTML or JavaScript code through the vulnerable 'filter[AutoExecuteCmd]' parameter value in the view filter (filter.php) of ZoneMinder.